Vulnerability Description
Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to inject arbitrary web script or HTML via vectors involving unsafe usage of Element.innerHTML.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 8.0 |
| Djangoproject | Django | <= 1.8.13 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/137965/Django-3.3.0-Script-Insertion.htmlVDB Entry
- http://rhn.redhat.com/errata/RHSA-2016-1594.html
- http://rhn.redhat.com/errata/RHSA-2016-1595.html
- http://rhn.redhat.com/errata/RHSA-2016-1596.html
- http://seclists.org/fulldisclosure/2016/Jul/53Mailing ListPatch
- http://www.debian.org/security/2016/dsa-3622Third Party Advisory
- http://www.securityfocus.com/archive/1/538947/100/0/threaded
- http://www.securityfocus.com/bid/92058
- http://www.securitytracker.com/id/1036338VDB Entry
- http://www.ubuntu.com/usn/USN-3039-1Third Party Advisory
- http://www.vulnerability-lab.com/get_content.php?id=1869PatchThird Party Advisory
- https://github.com/django/django/commit/d03bf6fe4e9bf5b07de62c1a271c4b41a7d3d158Patch
- https://github.com/django/django/commit/f68e5a99164867ab0e071a936470958ed867479dPatch
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2016-6186?
CVE-2016-6186 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and...
How severe is CVE-2016-6186?
CVE-2016-6186 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-6186?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Djangoproject Django.