Medium severity6.1NVD Advisory· Published Aug 1, 2018· Updated Jun 17, 2026
CVE-2016-8639
CVE-2016-8639
Description
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:a:redhat:satellite_capsule:6.3:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*range: <1.13.0
- (no CPE)range: <1.13.0
- (no CPE)range: 1.13.0
Patches
Vulnerability mechanics
References
5- www.securityfocus.com/bid/94263nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2018:0336nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- github.com/theforeman/foreman/pull/3523nvdThird Party Advisory
- projects.theforeman.org/issues/15037nvdVendor Advisory
News mentions
0No linked articles in our index yet.