CVE-2026-47687
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Summary
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the selectForm() helper in fogpage.class.php renders <option> labels using raw, unescaped user input. An unauthenticated attacker who knows any registered host's MAC address can POST a malicious sysproduct value to /service/inventory.php, which is stored in the database. When an administrator opens Reports > Inventory, the payload breaks out of the <option> element and executes arbitrary JavaScript in the admin's browser. Versions 1.5.10.1832 and 1.6.0-beta.2313 fix the issue.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| FOGProject | fogproject | < 1.5.10.1832 | affected |
| FOGProject | fogproject | < 1.6.0-beta.2313 | affected |
Weaknesses
- CWE-79: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: total
Additional References
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.