FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the unauthenticated inventory service endpoint (`/service/inventory.php`) persists client-supplied values without sanitization, and the Host Management Inventory page renders all static inventory fields into HTML without output encoding, allowing stored cross-site scripting that executes in any administrator's browser. Versions 1.5.10.1832 and 1.6.0-beta.2313 fix the issue.
References
| Link | Resource |
|---|---|
| https://github.com/FOGProject/fogproject/security/advisories/GHSA-2r7m-6mqf-5cc4 | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-07-21 21:16
Updated : 2026-08-07 13:50
NVD link : CVE-2026-47685
Mitre link : CVE-2026-47685
CVE.ORG link : CVE-2026-47685
JSON object : View
Products Affected
fogproject
- fogproject
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
