CVE-2015-2796
Last modified
CVE-2015-2796 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote attackers to inject arbitrary web script or HTML via the search_for parameter to (1) search_by_tag.php, (2) search_contacts.php, or (3) search.php.. EPSS estimates a 1.08% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote attackers to inject arbitrary web script or HTML via the search_for parameter to (1) search_by_tag.php, (2) search_contacts.php, or (3) search.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Projectpier | Projectpier | 0.8.8 |
References
- https://github.com/Project-Pier/ProjectPier-Core/commit/74ecbd4e939a65ba643a4af05fbdb1bb66992435Patch, Third Party Advisory
- https://github.com/Project-Pier/ProjectPier-Core/issues/37Exploit, Third Party Advisory
- https://github.com/Project-Pier/ProjectPier-Core/commit/74ecbd4e939a65ba643a4af05fbdb1bb66992435Patch, Third Party Advisory
- https://github.com/Project-Pier/ProjectPier-Core/issues/37Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-2796?
How severe is CVE-2015-2796?
How do I fix CVE-2015-2796?
Are you affected by CVE-2015-2796?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
