{"api_version":"1","generated_at":"2026-07-24T01:14:50+00:00","cve":"CVE-2016-8639","urls":{"html":"https://cve.report/CVE-2016-8639","api":"https://cve.report/api/cve/CVE-2016-8639.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-8639","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-8639"},"summary":{"title":"CVE-2016-8639","description":"It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2018-08-01 13:29:00","updated_at":"2023-11-07 02:36:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/94263","name":"94263","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Foreman CVE-2016-8639 Multiple HTML Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://projects.theforeman.org/issues/15037","name":"https://projects.theforeman.org/issues/15037","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Refactor #15037: Improve editable elements - Foreman","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/theforeman/foreman/pull/3523","name":"https://github.com/theforeman/foreman/pull/3523","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"Fixes #15037 - Improves editable elements in settings by amirfefer · Pull Request #3523 · theforeman/foreman · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8639","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8639","refsource":"CONFIRM","tags":["Issue Tracking","Third Party Advisory"],"title":"1393291 – (CVE-2016-8639) CVE-2016-8639 foreman: Stored XSS via organization/location with HTML in name","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2018:0336","name":"RHSA-2018:0336","refsource":"REDHAT","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-8639","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-8639","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"8639","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"satellite","cpe6":"6.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"8639","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"satellite","cpe6":"6.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"8639","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"satellite_capsule","cpe6":"6.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"8639","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"satellite_capsule","cpe6":"6.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"8639","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"theforeman","cpe5":"foreman","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"8639","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"theforeman","cpe5":"foreman","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2016-8639","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"foreman","version":{"version_data":[{"version_value":"1.13.0"}]}}]},"vendor_name":"The Foreman Project"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface."}]},"impact":{"cvss":[[{"vectorString":"6.1/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.0"}],[{"vectorString":"4.9/AV:N/AC:M/Au:S/C:P/I:P/A:N","version":"2.0"}]]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-79"}]}]},"references":{"reference_data":[{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8639","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8639"},{"name":"RHSA-2018:0336","refsource":"REDHAT","url":"https://access.redhat.com/errata/RHSA-2018:0336"},{"name":"https://github.com/theforeman/foreman/pull/3523","refsource":"CONFIRM","url":"https://github.com/theforeman/foreman/pull/3523"},{"name":"94263","refsource":"BID","url":"http://www.securityfocus.com/bid/94263"},{"name":"https://projects.theforeman.org/issues/15037","refsource":"CONFIRM","url":"https://projects.theforeman.org/issues/15037"}]}},"nvd":{"publishedDate":"2018-08-01 13:29:00","lastModifiedDate":"2023-11-07 02:36:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*","versionEndExcluding":"1.13.0","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:satellite:6.3:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:satellite_capsule:6.3:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"8639","Ordinal":"95294","Title":"CVE-2016-8639","CVE":"CVE-2016-8639","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"8639","Ordinal":"1","NoteData":"It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"8639","Ordinal":"2","NoteData":"2018-08-01","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"8639","Ordinal":"3","NoteData":"2018-08-02","Type":"Other","Title":"Modified"}]}}}