An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-09-25T22:59:16

Updated: 2021-12-28T12:06:15

Reserved: 2019-09-25T00:00:00


Link: CVE-2017-18635

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-09-25T23:15:09.937

Modified: 2022-04-06T17:54:34.933


Link: CVE-2017-18635

JSON object: View

cve-icon Redhat Information

No data.

CWE