CVE-2017-15214
Summary
| CVE | CVE-2017-15214 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-11 01:32:00 UTC |
| Updated | 2017-10-27 18:54:00 UTC |
| Description | Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges and also to execute JavaScript against other users (including unauthenticated users), via the name, title, or id parameter to plugins/dokuwiki/lib/plugins/changelinks/syntax.php. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Stored XSS vulnerabilities in Flyspray | MISC | openwall.com | Mailing List, Patch, Third Party Advisory, VDB Entry |
| quickfix for dokuwiki links · Flyspray/flyspray@00cfae5 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Release Flyspray 1.0-rc6 · Flyspray/flyspray · GitHub | MISC | github.com | Release Notes, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.