CVE-2015-3432: XSS
Published Sep 19, 2017
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in Pydio (formerly AjaXplorer) before 6.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Pydio XSS Vulnerabilities."
Affected Software
1 affected component
Pydio Pydio<=6.0.6
Remediation
Event History
Sep 19, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3432?
CVE-2015-3432 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2015-3432?
To fix CVE-2015-3432, upgrade Pydio to version 6.0.7 or later where the vulnerability has been patched.
3
What types of attacks are possible with CVE-2015-3432?
CVE-2015-3432 allows remote attackers to conduct cross-site scripting (XSS) attacks, injecting arbitrary web scripts or HTML.
4
Which versions of Pydio are affected by CVE-2015-3432?
CVE-2015-3432 affects all versions of Pydio prior to 6.0.7.
5
Is there a workaround for CVE-2015-3432 if I can't upgrade?
There are no known workarounds for CVE-2015-3432, so upgrading to a secure version is the recommended course of action.