CVE-2015-0298: XSS
Published Aug 24, 2015
·Updated
Cross-site scripting (XSS) vulnerability in the manager web interface in modcluster before 1.3.2.Alpha1 allows remote attackers to inject arbitrary web script or HTML via a crafted MCMP message.
Affected Software
1 affected component
redhat Mod Cluster<=1.3.1
Event History
Aug 24, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0298?
CVE-2015-0298 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2015-0298?
To mitigate CVE-2015-0298, upgrade mod_cluster to version 1.3.2.Alpha1 or later.
3
What systems are affected by CVE-2015-0298?
CVE-2015-0298 affects mod_cluster versions prior to 1.3.2.Alpha1.
4
What type of vulnerability is CVE-2015-0298?
CVE-2015-0298 is a cross-site scripting (XSS) vulnerability allowing remote attackers to inject scripts.
5
Can CVE-2015-0298 lead to data breaches?
Yes, CVE-2015-0298 can lead to data breaches through the exploitation of the XSS vulnerability.