{"api_version":"1","generated_at":"2026-07-23T07:39:37+00:00","cve":"CVE-2015-1864","urls":{"html":"https://cve.report/CVE-2015-1864","api":"https://cve.report/api/cve/CVE-2015-1864.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-1864","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-1864"},"summary":{"title":"CVE-2015-1864","description":"Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name user details, or the (3) repository, (4) repository group, or (5) user group description.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2017-09-19 15:29:00","updated_at":"2020-05-28 16:59:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://kallithea-scm.org/security/cve-2015-1864.html","name":"https://kallithea-scm.org/security/cve-2015-1864.html","refsource":"CONFIRM","tags":["Exploit","Vendor Advisory"],"title":"Kallithea · Security Notice CVE-2015-1864","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/74184","name":"74184","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Kallithea CVE-2015-1864 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2015/04/14/12","name":"[oss-security] 20150414 CVE-2015-1864: Multiple HTML and Javascript injections","refsource":"MLIST","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"oss-security - CVE-2015-1864: Multiple HTML and Javascript injections","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://kallithea-scm.org/repos/kallithea/changeset/a8f2986afc18c9221bf99f88b06e60ab83c86c55","name":"https://kallithea-scm.org/repos/kallithea/changeset/a8f2986afc18c9221bf99f88b06e60ab83c86c55","refsource":"CONFIRM","tags":["Patch"],"title":"kallithea Changeset - a8f2986afc18\n\n    · Our Own Kallithea","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-1864","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1864","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"1864","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kallithea-scm","cpe5":"kallithea","cpe6":"0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"1864","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kallithea-scm","cpe5":"kallithea","cpe6":"0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"1864","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kallithea-scm","cpe5":"kallithea","cpe6":"0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"1864","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kallithea-scm","cpe5":"kallithea","cpe6":"0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2015-1864","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name user details, or the (3) repository, (4) repository group, or (5) user group description."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://kallithea-scm.org/security/cve-2015-1864.html","refsource":"CONFIRM","url":"https://kallithea-scm.org/security/cve-2015-1864.html"},{"name":"74184","refsource":"BID","url":"http://www.securityfocus.com/bid/74184"},{"name":"[oss-security] 20150414 CVE-2015-1864: Multiple HTML and Javascript injections","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2015/04/14/12"},{"name":"https://kallithea-scm.org/repos/kallithea/changeset/a8f2986afc18c9221bf99f88b06e60ab83c86c55","refsource":"CONFIRM","url":"https://kallithea-scm.org/repos/kallithea/changeset/a8f2986afc18c9221bf99f88b06e60ab83c86c55"}]}},"nvd":{"publishedDate":"2017-09-19 15:29:00","lastModifiedDate":"2020-05-28 16:59:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:kallithea-scm:kallithea:0.1:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:kallithea-scm:kallithea:0.2:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"1864","Ordinal":"78759","Title":"CVE-2015-1864","CVE":"CVE-2015-1864","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"1864","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name user details, or the (3) repository, (4) repository group, or (5) user group description.","Type":"Description","Title":null},{"CveYear":"2015","CveId":"1864","Ordinal":"2","NoteData":"2017-09-19","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"1864","Ordinal":"3","NoteData":"2017-09-19","Type":"Other","Title":"Modified"}]}}}