SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-15215

Reflected XSS vulnerability in Shaarli v0.9.1 allows an unauthenticated attacker to inject JavaScript via the searchtags parameter to index.php.

MEDIUM 6.1EPSS 1.49%

Does this matter?

Lower severity and a low EPSS score (1.49%). Track it; it rarely justifies an emergency change on its own.

Description

Reflected XSS vulnerability in Shaarli v0.9.1 allows an unauthenticated attacker to inject JavaScript via the searchtags parameter to index.php. If the victim is an administrator, an attacker can (for example) take over the admin session or change global settings or add/delete links. It is also possible to execute JavaScript against unauthenticated users.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
1.49% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
shaarli project/shaarli
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.