CVE-2018-5249
Summary
| CVE | CVE-2018-5249 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-05 20:29:00 UTC |
| Updated | 2018-01-17 14:50:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php). |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Shaarli Project | Shaarli | All | All | All | All |
| Application | Shaarli Project | Shaarli | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release v0.8.5 · shaarli/Shaarli · GitHub | CONFIRM | github.com | Third Party Advisory |
| Fix XSS vulnerability by virtualtam · Pull Request #1046 · shaarli/Shaarli · GitHub | CONFIRM | github.com | Release Notes, Third Party Advisory |
| Release v0.9.3 · shaarli/Shaarli · GitHub | CONFIRM | github.com | Release Notes, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.