CVE-2016-8639
published 2018-08-01CVE-2016-8639: It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set…
PriorityP427medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
1.16%
63.5th percentile
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
| redhat | satellite_capsule | — | — |
| the_foreman_project | foreman | — | — |
| theforeman | foreman | < 1.13.0 | 1.13.0 |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
foreman: Stored XSS via organization/location with HTML in name
vendor_redhat·2016-05-12·CVSS 6.1
CVE-2016-8639 [MEDIUM] CWE-79 foreman: Stored XSS via organization/location with HTML in name
foreman: Stored XSS via organization/location with HTML in name
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.
It was found that foreman is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.
Package: foreman (Red Hat Ceph Storage 1.3) - Will not fix
GHSA
GHSA-mwqr-rg79-hjrr: It was found that foreman before 1
ghsa_unreviewed·2022-05-13
CVE-2016-8639 [MEDIUM] CWE-79 GHSA-mwqr-rg79-hjrr: It was found that foreman before 1
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/94263https://access.redhat.com/errata/RHSA-2018:0336https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8639https://github.com/theforeman/foreman/pull/3523https://projects.theforeman.org/issues/15037http://www.securityfocus.com/bid/94263https://access.redhat.com/errata/RHSA-2018:0336https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8639https://github.com/theforeman/foreman/pull/3523https://projects.theforeman.org/issues/15037
2018-08-01
Published