CVE-2016-0926
Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before 1.7.8 allows remote attackers to inject arbitrary web script or HTML via unspecified input that improperly interacts…
Does this matter?
Lower severity and a low EPSS score (1.12%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before 1.7.8 allows remote attackers to inject arbitrary web script or HTML via unspecified input that improperly interacts with the AngularJS framework.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.12% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- pivotal software/cloud foundry elastic runtime
- Source
- security_alert@emc.com
References
- http://www.securityfocus.com/bid/91677Third Party Advisory, VDB Entry
- https://pivotal.io/security/cve-2016-0926Vendor Advisory
- http://www.securityfocus.com/bid/91677Third Party Advisory, VDB Entry
- https://pivotal.io/security/cve-2016-0926Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.