Back to search
CVE-2018-1096
Published: Apr 5, 2018
Modified: Sep 16, 2024
PUBLISHED
Description
An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.
| Vendor | Product | Versions |
|---|---|---|
Foreman Project | Foreman | affected before 1.16.1 |
Weaknesses (CWE)
References
RHSA-2018:2927
vendor-advisory
x_refsource_REDHAT
https://bugzilla.redhat.com/show_bug.cgi?id=1561061
x_refsource_CONFIRM
http://projects.theforeman.org/issues/23028
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now