It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.
Project Subscriptions
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-9481 | It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T02:27:41.125Z
Reserved: 2016-10-12T00:00:00.000Z
Link: CVE-2016-8639
No data.
Status : Modified
Published: 2018-08-01T13:29:00.310
Modified: 2024-11-21T02:59:44.487
Link: CVE-2016-8639
OpenCVE Enrichment
No data.
Weaknesses
EUVD