CVE-2016-0926: XSS
Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before 1.7.8 allows remote attackers to inject arbitrary web script or HTML via unspecified input that improperly interacts with the AngularJS framework.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0926?
CVE-2016-0926 is considered a high-severity cross-site scripting vulnerability that allows remote code injection.
How do I fix CVE-2016-0926?
To fix CVE-2016-0926, upgrade Pivotal Cloud Foundry Elastic Runtime to version 1.6.32 or later, or 1.7.8 or later.
What software is affected by CVE-2016-0926?
CVE-2016-0926 affects Pivotal Cloud Foundry Elastic Runtime versions prior to 1.6.32 and 1.7.x before 1.7.8.
What types of attacks can CVE-2016-0926 facilitate?
CVE-2016-0926 can facilitate remote attackers to inject arbitrary web scripts or HTML through cross-site scripting attacks.
When was CVE-2016-0926 discovered?
CVE-2016-0926 was publicly disclosed in 2016.