CVE-2016-10245

Related Vulnerabilities: CVE-2016-10245  

Impact: Low Public Date: 2019-05-24 CWE: CWE-352 Bugzilla: 1714190: CVE-2016-10245 doxygen: cross-site scripting in templates/html/search_opensearch.php Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection.

The MITRE CVE dictionary describes this issue as:

Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection.

Find out more about CVE-2016-10245 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 3.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction Required
Scope Unchanged
Confidentiality None
Integrity Impact Low
Availability Impact None

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 8 doxygen Under investigation
Red Hat Enterprise Linux 7 doxygen Under investigation
Red Hat Enterprise Linux 6 doxygen Under investigation
Red Hat Enterprise Linux 5 doxygen Under investigation