Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106418
Category:Web application abuses
Title:Foreman 1.6.x < 1.12.2 XSS Vulnerability
Summary:Foreman is prone to a cross-site scripting (XSS); vulnerability.
Description:Summary:
Foreman is prone to a cross-site scripting (XSS)
vulnerability.

Vulnerability Insight:
Label parameter of all form helpers was not escaped allowing
XSS. The Foreman itself did not contain exploitable code but other plugins that relied on form
helpers could be vulnerable. One known vulnerable plugin is Remote Execution.

Affected Software/OS:
Foreman versions 1.6.x through 1.12.1.

Solution:
Update to version 1.12.2 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-6319
92429
http://www.securityfocus.com/bid/92429
RHSA-2018:0336
https://access.redhat.com/errata/RHSA-2018:0336
http://projects.theforeman.org/issues/16019
http://projects.theforeman.org/issues/16024
https://bugzilla.redhat.com/show_bug.cgi?id=1365815
https://github.com/theforeman/foreman/commit/0f35fe14acf0d0d3b55e9337bc5e2b9640ff2372
https://theforeman.org/security.html#2016-6319
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.