6.1
CVSSv3

CVE-2016-3113

Published: 07/08/2017 Updated: 18/02/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote malicious users to inject arbitrary web script or HTML.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ovirt-engine -

Vendor Advisories

Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML ...

Github Repositories

A proof of concept to exploit the reflected XSS vulnerability in the oVirt web interface (RedHat). In this PoC a VM in the oVirt IaaS environment is to be started via the victim's browser session. JS code has been kept simple due to the rush.

CVE-2016-3113 (PoC) A proof of concept to exploit the reflected XSS vulnerability in the oVirt web interface (RedHat) In this PoC a VM in the oVirt IaaS environment is to be started via the victim's browser session JS code has been kept simple due to the rush More Info here: wwwitskritisde/_uploads/jk17/Students___Freigabeversion/DURMAZ___Praesentationpdf (sl