---
id: CVE-2016-6519
aliases:
  - GHSA-vq76-5ghr-9p4v
  - PYSEC-2026-662
title: Openstack Manila Persistent XSS in Metadata field
summary: Openstack Manila Persistent XSS in Metadata field
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
vendor: manila-ui
product: manila-ui
ecosystem: pip
affected:
  - manila-ui < 2.5.1
patched:
  - manila-ui 2.5.1
published: '2022-05-13'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-vq76-5ghr-9p4v'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2016-6519'
  - url: >-
      https://github.com/openstack/manila-ui/commit/009913d725bee34cef0bd62e47a298025ace2696
  - url: >-
      https://github.com/openstack/manila-ui/commit/89593686ef18f2bd06223b92071b4be2362a5abd
  - url: >-
      https://github.com/openstack/manila-ui/commit/fca19a1b0d42536644212c5d673fbd6866e67c43
  - url: 'https://bugs.launchpad.net/manila-ui/+bug/1597738'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1375147'
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2115.html'
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2116.html'
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-2117.html'
  - url: 'http://www.openwall.com/lists/oss-security/2016/09/15/7'
  - url: 'http://www.securityfocus.com/bid/93001'
tags:
  - osv
  - pip
epss: 0.01665
epssPercentile: 0.75316
ingestedAt: '2026-07-08T18:25:53.356Z'
---

## Overview

Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" form.

## Affected packages

- `manila-ui < 2.5.1`

## Remediation

Upgrade to a patched release:

- `manila-ui 2.5.1`
