What the vulnerability does

01Description

An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.

Key dates

02Disclosure timeline

April 5, 2018 CVE published
September 16, 2024 Record updated