3.5
CVSSv2

CVE-2016-6519

Published: 21/04/2017 Updated: 07/11/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila prior to 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" form.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openstack 7.0

redhat openstack 9

redhat openstack 8

openstack manila

Vendor Advisories

Debian Bug report logs - #838017 manila-ui: CVE-2016-6519: persistent XSS in metadata field Package: src:manila-ui; Maintainer for src:manila-ui is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 16 Sep 2016 13:03:07 UTC Severity: grave Tags: patc ...
Synopsis Moderate: openstack-manila-ui security update Type/Severity Security Advisory: Moderate Topic An update for openstack-manila-ui is now available for Red Hat OpenStack Platform 90 (Mitaka)Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability ...
Synopsis Moderate: openstack-manila-ui security update Type/Severity Security Advisory: Moderate Topic An update for openstack-manila-ui is now available for Red Hat OpenStack Platform 80 (Liberty)Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabilit ...
Synopsis Moderate: openstack-manila-ui security update Type/Severity Security Advisory: Moderate Topic An update for openstack-manila-ui is now available for Red Hat Enterprise Linux OpenStack Platform 70 (Kilo) for RHEL 7Red Hat Product Security has rated this update as having a security impact of Modera ...
A cross-site scripting flaw was discovered in openstack-manila-ui's Metadata field contained in its "Create Share" form A user could inject malicious HTML/JavaScript code that would then be reflected in the "Shares" overview Remote, authenticated, but unprivileged users could exploit this vulnerability to steal session cookies and escalate their ...