Vulnerability Description
An issue was discovered in Skybox Platform before 7.5.401. Reflected cross-site scripting vulnerabilities exist in /skyboxview/webservice/services/VersionRepositoryWebService via a soapenv:Body element, or in the status parameter to login.html.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Skyboxsecurity | Skybox Platform | < 7.5.401 |
Related Weaknesses (CWE)
References
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20151210-ExploitThird Party Advisory
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20151210-ExploitThird Party Advisory
FAQ
What is CVE-2015-9247?
CVE-2015-9247 is a vulnerability with a CVSS score of 5.4 (MEDIUM). An issue was discovered in Skybox Platform before 7.5.401. Reflected cross-site scripting vulnerabilities exist in /skyboxview/webservice/services/VersionRepositoryWebService via a soapenv:Body elemen...
How severe is CVE-2015-9247?
CVE-2015-9247 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-9247?
Check the references section above for vendor advisories and patch information. Affected products include: Skyboxsecurity Skybox Platform.