CVE Database
/

CVE-2016-6186

Back to search

CVE-2016-6186

Published: Aug 5, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to inject arbitrary web script or HTML via vectors involving unsafe usage of Element.innerHTML.

VendorProductVersions

n/a

n/a

affected
n/a

References

1036338
vdb-entry
x_refsource_SECTRACK
RHSA-2016:1594
vendor-advisory
x_refsource_REDHAT
DSA-3622
vendor-advisory
x_refsource_DEBIAN
FEDORA-2016-97ca9d52a4
vendor-advisory
x_refsource_FEDORA
USN-3039-1
vendor-advisory
x_refsource_UBUNTU
FEDORA-2016-b7e31a0b9a
vendor-advisory
x_refsource_FEDORA
RHSA-2016:1596
vendor-advisory
x_refsource_REDHAT
92058
vdb-entry
x_refsource_BID
RHSA-2016:1595
vendor-advisory
x_refsource_REDHAT
40129
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now