CVE-2015-3921: XSS
Published May 27, 2015
·Updated
Cross-site scripting (XSS) vulnerability in contact.php in Coppermine Photo Gallery before 1.5.36 allows remote authenticated users to inject arbitrary web script or HTML via the referer parameter.
Affected Software
1 affected component
Coppermine-gallery Coppermine Photo Gallery<=1.5.34
Event History
May 27, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3921?
CVE-2015-3921 is categorized as a moderate severity cross-site scripting vulnerability.
2
How do I fix CVE-2015-3921?
To fix CVE-2015-3921, upgrade Coppermine Photo Gallery to version 1.5.36 or later.
3
Who is affected by CVE-2015-3921?
CVE-2015-3921 affects remote authenticated users of Coppermine Photo Gallery versions prior to 1.5.36.
4
What does CVE-2015-3921 allow an attacker to do?
CVE-2015-3921 allows an attacker to inject arbitrary web script or HTML through the referer parameter.
5
In which component of Coppermine is CVE-2015-3921 found?
CVE-2015-3921 is found in the contact.php component of Coppermine Photo Gallery.