Sal is a multi-tenanted reporting dashboard for Munki with the ability to display information from Facter. In Sal through version 4.1.6 there is an XSS vulnerability on the machine_list view.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26205
Reference (s):
- https://github.com/salopensource/sal/pull/405
- URL: https://github.com/salopensource/sal/pull/405
- https://github.com/salopensource/sal/commit/145bb72daf8460bdedbbc9fb708d346283e7a568
- URL: https://github.com/salopensource/sal/commit/145bb72daf8460bdedbbc9fb708d346283e7a568

