Bug #16022
closed
CVE-2016-6320 - Network interface device identifiers may contain stored XSS on host form
Added by Dominic Cleal over 8 years ago.
Updated over 6 years ago.
Description
Network interface identifiers stored for hosts may contain HTML or JavaScript that allows a stored XSS (cross-site scripting) vulnerability when later viewing the host edit form.
This issue was reported by Sanket Jagtap.
CVE identifier will be assigned.
- Status changed from New to Ready For Testing
- Assignee set to Tomer Brisker
- Pull request https://github.com/theforeman/foreman/pull/3714 added
- Target version set to 1.7.1
- Status changed from Ready For Testing to Closed
- % Done changed from 0 to 100
- Subject changed from Network interface device identifiers may contain stored XSS on host form to CVE-2016-6320 - Network interface device identifiers may contain stored XSS on host form
- Target version changed from 1.7.1 to 1.6.2
- Target version changed from 1.6.2 to 1.7.1
- Bugzilla link set to 1421803
Also available in: Atom
PDF