First published: Sun Mar 29 2015(Updated: )
Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openid_identifier parameter in a verify action to ikiwiki.cgi.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ikiwiki | <3.20150329 | 3.20150329 |
debian/ikiwiki | 3.20200202.3-1 3.20200202.4-2 | |
Ikiwiki Hosting Project | <3.20150329 | |
Fedora | =20 | |
Fedora | =21 | |
Fedora | =22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2793 is considered a medium severity vulnerability due to its impact on user input and potential for exploitation.
To fix CVE-2015-2793, upgrade to ikiwiki version 3.20150329 or later.
CVE-2015-2793 affects ikiwiki versions prior to 3.20150329 across multiple Linux distributions including Red Hat and Debian.
CVE-2015-2793 is a Cross-Site Scripting (XSS) vulnerability allowing remote attackers to inject arbitrary web scripts.
Exploiting CVE-2015-2793 could allow an attacker to execute malicious scripts in the context of the user's browser.