Search Results (22 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2012-2094 1 Openstack 1 Horizon 2024-08-06 N/A
Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon.js in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the guest console.
CVE-2013-4471 1 Openstack 1 Horizon 2024-08-06 N/A
The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.