An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.Referenceshttps://access.redhat.com/errata/RHSA-2018:2927https://bugzilla.redhat.com/show_bug.cgi?id=1561061http://projects.theforeman.org/issues/23028