Back

HIGH

Controller: html injection in custom login info

Published Oct 4, 2023

Description

An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 4, 2023
Updated Nov 20, 2025
Reserved Jul 27, 2023
CISA Vulnrichment
Updated Apr 26, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 27, 2023