Vulnerability Description
Cross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers to inject arbitrary web script or HTML via the scripts parameter to media/unit_testing/templates/6776.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sprymedia | Datatables | <= 1.10.8 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/133555/DataTables-1.10.8-Cross-Site-Scripti
- http://seclists.org/fulldisclosure/2015/Sep/37
- http://www.securityfocus.com/archive/1/536437/100/0/threaded
- https://www.netsparker.com/cve-2015-6384-xss-vulnerability-identified-in-datatabExploit
- http://packetstormsecurity.com/files/133555/DataTables-1.10.8-Cross-Site-Scripti
- http://seclists.org/fulldisclosure/2015/Sep/37
- http://www.securityfocus.com/archive/1/536437/100/0/threaded
- https://www.netsparker.com/cve-2015-6384-xss-vulnerability-identified-in-datatabExploit
FAQ
What is CVE-2015-6584?
CVE-2015-6584 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers to inject arbitrary web script or HTML via the scripts parameter to media/unit_t...
How severe is CVE-2015-6584?
CVE-2015-6584 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-6584?
Check the references section above for vendor advisories and patch information. Affected products include: Sprymedia Datatables.