Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6186

Опубликовано: 18 июл. 2016
Источник: redhat
CVSS3: 6.1
CVSS2: 4.3
EPSS Средний

Описание

Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to inject arbitrary web script or HTML via vectors involving unsafe usage of Element.innerHTML.

A cross-site scripting (XSS) flaw was found in Django. An attacker could exploit the unsafe usage of JavaScript's Element.innerHTML to forge content in the admin's add/change related pop-up. Element.textContent is now used to prevent XSS data execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.3DjangoWill not fix
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)python-djangoNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)python-djangoNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Toolspython-djangoNot affected
Red Hat OpenStack Platform 10 (Newton)python-djangoNot affected
Red Hat OpenStack Platform 9 (Mitaka)python-djangoNot affected
Red Hat Subscription Asset ManagerDjangoWill not fix
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7python-djangoFixedRHSA-2016:159511.08.2016
Red Hat OpenStack Platform 8.0 (Liberty)python-djangoFixedRHSA-2016:159611.08.2016
Red Hat OpenStack Platform 8.0 Operational Tools for RHEL 7python-djangoFixedRHSA-2016:159410.08.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1355663django: XSS in admin's add/change related popup

EPSS

Процентиль: 94%
0.13095
Средний

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 9 лет назад

Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to inject arbitrary web script or HTML via vectors involving unsafe usage of Element.innerHTML.

CVSS3: 6.1
nvd
почти 9 лет назад

Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to inject arbitrary web script or HTML via vectors involving unsafe usage of Element.innerHTML.

CVSS3: 6.1
debian
почти 9 лет назад

Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedOb ...

CVSS3: 6.1
github
около 3 лет назад

Django Cross-site scripting Vulnerability

suse-cvrf
около 7 лет назад

Security update for python-Django

EPSS

Процентиль: 94%
0.13095
Средний

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Уязвимость CVE-2016-6186