{"id":"CVE-2016-3079","details":"Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems/SystemEntitlements.do; (2) the label parameter to admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot tag or (4) system group in System Set Manager (SSM).","modified":"2026-07-08T05:48:43.277877017Z","published":"2016-04-14T14:59:08.177Z","related":["SUSE-SU-2016:1367-1"],"database_specific":{"unresolved_ranges":[{"vendor_product":"redhat:satellite","cpes":["cpe:2.3:a:redhat:satellite:5.7:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"5.7"},{"last_affected":"5.7"}],"source":"CPE_STRING"}]},"references":[{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-0590.html"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1320444"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1320452"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1320940"},{"type":"FIX","url":"https://github.com/spacewalkproject/spacewalk/commit/7920542f"},{"type":"FIX","url":"https://github.com/spacewalkproject/spacewalk/commit/7b9ff9ad"},{"type":"FIX","url":"https://github.com/spacewalkproject/spacewalk/commit/982b11c9"},{"type":"FIX","url":"https://github.com/spacewalkproject/spacewalk/commit/b6491eba"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/spacewalkproject/spacewalk","events":[{"introduced":"0"},{"fixed":"7920542f"},{"fixed":"7b9ff9ad"},{"fixed":"982b11c9"},{"fixed":"b6491eba"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-3079.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}