Cross-site scripting (XSS) vulnerability in the console in Puppet Enterprise before 2015.2.1 allows remote attackers to inject arbitrary web script or HTML via the string parameter, related to Login Redirect.
- https://puppet.com/security/cve/CVE-2015-6502
- https://github.com/ARPSyndicate/cvemon