Vulnerability Description
Cross-site scripting (XSS) vulnerability in SnipSnap 0.5.2a, 1.0b1, and 1.0b2 allows remote attackers to inject arbitrary web script or HTML via the query parameter to /snipsnap-search.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Snipsnap | Snipsnap | 0.5.2a |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2015/Feb/1
- http://tetraph.com/security/cves/cve-2014-9559-snipsnap-xss-cross-site-scripting
- http://seclists.org/fulldisclosure/2015/Feb/1
- http://tetraph.com/security/cves/cve-2014-9559-snipsnap-xss-cross-site-scripting
FAQ
What is CVE-2014-9559?
CVE-2014-9559 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in SnipSnap 0.5.2a, 1.0b1, and 1.0b2 allows remote attackers to inject arbitrary web script or HTML via the query parameter to /snipsnap-search.
How severe is CVE-2014-9559?
CVE-2014-9559 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-9559?
Check the references section above for vendor advisories and patch information. Affected products include: Snipsnap Snipsnap.