Vulnerability Description
Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges and also to execute JavaScript against other users (including unauthenticated users), via the name, title, or id parameter to plugins/dokuwiki/lib/plugins/changelinks/syntax.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Flyspray | Flyspray | 1.0 |
Related Weaknesses (CWE)
References
- http://openwall.com/lists/oss-security/2017/10/07/1Mailing ListPatchThird Party Advisory
- https://github.com/Flyspray/flyspray/commit/00cfae5661124f9d67ac6733db61b2bfee34PatchThird Party Advisory
- https://github.com/Flyspray/flyspray/releases/tag/v1.0-rc6Release NotesThird Party Advisory
- http://openwall.com/lists/oss-security/2017/10/07/1Mailing ListPatchThird Party Advisory
- https://github.com/Flyspray/flyspray/commit/00cfae5661124f9d67ac6733db61b2bfee34PatchThird Party Advisory
- https://github.com/Flyspray/flyspray/releases/tag/v1.0-rc6Release NotesThird Party Advisory
FAQ
What is CVE-2017-15214?
CVE-2017-15214 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges and also to execute JavaScript against other users (inclu...
How severe is CVE-2017-15214?
CVE-2017-15214 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15214?
Check the references section above for vendor advisories and patch information. Affected products include: Flyspray Flyspray.