ikiwiki 'openid_identifier' Parameter Cross Site Scripting Vulnerability
BID:73198
Info
ikiwiki 'openid_identifier' Parameter Cross Site Scripting Vulnerability
| Bugtraq ID: | 73198 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-2793 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 30 2015 12:00AM |
| Updated: | Mar 30 2015 12:00AM |
| Credit: | Salvatore Bonaccorso |
| Vulnerable: |
ikiwiki ikiwiki 3.20141016.1 |
| Not Vulnerable: |
ikiwiki ikiwiki 3.20141016.2 ikiwiki ikiwiki 3.20150329 |
Discussion
ikiwiki 'openid_identifier' Parameter Cross Site Scripting Vulnerability
ikiwiki is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
ikiwiki is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
References
ikiwiki 'openid_identifier' Parameter Cross Site Scripting Vulnerability
References:
References:
- Fix XSS in openid selector. Thanks, Raghav Bisht. (ikiwiki)
- ikiwiki Homepage (ikiwiki)
- ikiwiki: CVE-2015-2793: cross-site scripting via openid_identifier (bugs.debian)