CVE-2015-3296: XSS
Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript: or (2) data: URLs.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3296?
CVE-2015-3296 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-3296?
To fix CVE-2015-3296, upgrade NodeBB to version 0.7.0 or higher, or ensure you are using nodebb-plugin-markdown version 5.1.1 or later.
What versions are affected by CVE-2015-3296?
CVE-2015-3296 affects NodeBB versions up to and including 0.6.1 and nodebb-plugin-markdown versions prior to 5.1.1.
Can CVE-2015-3296 be exploited remotely?
Yes, CVE-2015-3296 can be exploited remotely, allowing attackers to inject arbitrary web scripts or HTML.
What types of vulnerabilities does CVE-2015-3296 include?
CVE-2015-3296 includes multiple cross-site scripting (XSS) vulnerabilities related to javascript: and data: URLs.