Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-8634

Опубликовано: 01 авг. 2018
Источник: nvd
CVSS3: 6.1
CVSS3: 5.4
CVSS2: 3.5
EPSS Низкий

Описание

A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of the wizard (/organizations/id/step2) will render the HTML. This occurs in the alertbox on the page. The result is a stored XSS attack if an organization/location with HTML in the name is created, then a user is linked directly to this URL.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:theforeman:foreman:1.14.0:*:*:*:*:*:*:*

EPSS

Процентиль: 55%
0.00328
Низкий

6.1 Medium

CVSS3

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 6.1
redhat
больше 9 лет назад

A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of the wizard (/organizations/id/step2) will render the HTML. This occurs in the alertbox on the page. The result is a stored XSS attack if an organization/location with HTML in the name is created, then a user is linked directly to this URL.

CVSS3: 6.1
debian
больше 7 лет назад

A vulnerability was found in foreman 1.14.0. When creating an organiza ...

CVSS3: 5.4
github
больше 3 лет назад

A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of the wizard (/organizations/id/step2) will render the HTML. This occurs in the alertbox on the page. The result is a stored XSS attack if an organization/location with HTML in the name is created, then a user is linked directly to this URL.

EPSS

Процентиль: 55%
0.00328
Низкий

6.1 Medium

CVSS3

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79