cbcvebase.
CVE-2016-8639
published 2018-08-01

CVE-2016-8639: It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set…

PriorityP427medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
1.16%
63.5th percentile
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.

Affected

4 ranges
VendorProductVersion rangeFixed in
redhatsatellite
redhatsatellite_capsule
the_foreman_projectforeman
theforemanforeman< 1.13.01.13.0

CVSS provenance

nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.