CVE-2026-33739 Details
Description
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.1812, the listing tables on multiple management pages (Host, Storage, Group, Image, Printer, Snapin) are vulnerable to Stored Cross-Site Scripting (XSS), due to insufficient server-side parameter sanitization in record creations/updates and a lack of HTML escaping in listing tables. Version 1.5.10.1812 patches the issue.
A stored cross-site scripting vulnerability has been identified in FOG Project versions prior to 1.5.10.1812. This issue affects the listing tables on several management pages, including Host, Storage, Group, Image, Printer, and Snapin. The vulnerability arises from inadequate server-side parameter sanitization during record creation and updates, coupled with a lack of HTML escaping in the listing tables. As a result, an attacker can inject malicious scripts that are executed in the context of the user viewing the page, potentially leading to session hijacking, unauthorized actions, data exfiltration, and execution of malicious scripts in the user's browser.
Users can update to FOG Project version 1.5.10.1812 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/FOGProject/fogproject/security/advisories/GHSA-8m2f-4x7g-p8f3 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| fogproject fogproject | < 1.5.10.1812 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 8, 2026 | Initial Analysis | [email protected] |
| Mar 27, 2026 | New CVE Received | [email protected] |