Stored XSS Vulnerability in Foreman by Red Hat
CVE-2016-8634
What is CVE-2016-8634?
A stored Cross-Site Scripting (XSS) vulnerability exists in Foreman 1.14.0. This issue arises when an organization or location is created with a name containing HTML elements. During the second step of the organization creation wizard, the system erroneously renders the HTML, leading to a scenario where an attacker can inject malicious scripts into the application. If a user accesses the specific URL linked to the affected organization or location, the injected HTML will execute in their browser, potentially compromising user data or session information. It is crucial for users of this application to sanitize input and validate data to mitigate the risk associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
foreman 1.14.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
