CVE-2015-2793: XSS
Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openididentifier parameter in a verify action to ikiwiki.cgi.
Other sources
Cross-site scripting flaw in the handling of the openididentifier parameterhas been fixed in ikiwiki:
http://source.ikiwiki.branchable.com/?p=source.git;a=commit;h=18dfba868fe2fb9c64706b2123eb0b3a3ce66a77
CVE request sent to oss-security.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2793?
CVE-2015-2793 is considered a medium severity vulnerability due to its impact on user input and potential for exploitation.
How do I fix CVE-2015-2793?
To fix CVE-2015-2793, upgrade to ikiwiki version 3.20150329 or later.
What systems are affected by CVE-2015-2793?
CVE-2015-2793 affects ikiwiki versions prior to 3.20150329 across multiple Linux distributions including Red Hat and Debian.
What type of vulnerability is CVE-2015-2793?
CVE-2015-2793 is a Cross-Site Scripting (XSS) vulnerability allowing remote attackers to inject arbitrary web scripts.
What is the impact of exploiting CVE-2015-2793?
Exploiting CVE-2015-2793 could allow an attacker to execute malicious scripts in the context of the user's browser.