VulnerabilityModified
CVE-2018-5249
Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php).
MEDIUM 6.1EPSS 1.50%
Does this matter?
Lower severity and a low EPSS score (1.50%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php).
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.50% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- shaarli project/shaarli
- Source
- cve@mitre.org
References
- https://github.com/shaarli/Shaarli/pull/1046Release Notes, Third Party Advisory
- https://github.com/shaarli/Shaarli/releases/tag/v0.8.5Third Party Advisory
- https://github.com/shaarli/Shaarli/releases/tag/v0.9.3Release Notes, Third Party Advisory
- https://github.com/shaarli/Shaarli/pull/1046Release Notes, Third Party Advisory
- https://github.com/shaarli/Shaarli/releases/tag/v0.8.5Third Party Advisory
- https://github.com/shaarli/Shaarli/releases/tag/v0.9.3Release Notes, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.