CVE-2016-6186
MEDIUM6.1EPSS 16.4%python-django - security update
Published: 5/14/2022Modified: 4/28/2026
Description
Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to inject arbitrary web script or HTML via vectors involving unsafe usage of Element.innerHTML.
Affected packages (5)
- Debian/python-djangofrom 0, < 1:1.9.8-1
- Debian/python-djangofrom 0, < 1.4.5-1+deb7u17
- Debian/python-djangofrom 0, < 1.7.7-1+deb8u5
- PyPI/djangofrom 0, < 1.8.14
- PyPI/djangofrom 0, < d03bf6fe4e9bf5b07de62c1a271c4b41a7d3d158, < f68e5a99164867ab0e071a936470958ed867479d | from 0, < 1.8.14, >= 1.9, < 1.9.8, >= 1.10a0, < 1.10rc1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
References (29)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2016-6186
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2016-6186
- ADVISORYhttps://www.djangoproject.com/weblog/2016/jul/18/security-releases/
- PATCHhttps://github.com/django/django
- WEBhttp://packetstormsecurity.com/files/137965/Django-3.3.0-Script-Insertion.html
- WEBhttp://rhn.redhat.com/errata/RHSA-2016-1594.html
- WEBhttp://rhn.redhat.com/errata/RHSA-2016-1595.html
- WEBhttp://rhn.redhat.com/errata/RHSA-2016-1596.html
- WEBhttp://seclists.org/fulldisclosure/2016/Jul/53
- WEBhttps://github.com/django/django/commit/6fa150b2f8b601668083042324c4add534143cb1
- WEBhttps://github.com/django/django/commit/d03bf6fe4e9bf5b07de62c1a271c4b41a7d3d158
- WEBhttps://github.com/django/django/commit/f68e5a99164867ab0e071a936470958ed867479d
- WEBhttps://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2016-2.yaml
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/DMLLFAUT4J4IP4P2KI4NOVWRMHA22WUJ
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/DMLLFAUT4J4IP4P2KI4NOVWRMHA22WUJ/
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/KHHPN6MISX5I6UTXQHYLPTLEEUE6WDXW
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/KHHPN6MISX5I6UTXQHYLPTLEEUE6WDXW/
- WEBhttps://web.archive.org/web/20201022155237/http://www.securityfocus.com/archive/1/538947/100/0/threaded
- WEBhttps://web.archive.org/web/20210123154652/http://www.securityfocus.com/bid/92058
- WEBhttps://web.archive.org/web/20211204042848/http://www.securitytracker.com/id/1036338
- WEBhttps://www.djangoproject.com/weblog/2016/jul/18/security-releases
- WEBhttps://www.exploit-db.com/exploits/40129
- WEBhttps://www.exploit-db.com/exploits/40129/
- WEBhttp://www.debian.org/security/2016/dsa-3622
- WEBhttp://www.securityfocus.com/archive/1/538947/100/0/threaded
- WEBhttp://www.securityfocus.com/bid/92058
- WEBhttp://www.securitytracker.com/id/1036338
- WEBhttp://www.ubuntu.com/usn/USN-3039-1
- WEBhttp://www.vulnerability-lab.com/get_content.php?id=1869