CVE-2015-3989: XSS
Published May 15, 2015
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to private messages or other unspecified vectors.
Affected Software
2 affected componentsFixes available
concrete5 concrete5<=5.7.3.1
composer/concrete5/concrete5<5.7.4
5.7.4
Remediation
Event History
May 15, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·03:29 AM
Frequently Asked Questions
1
What is the severity of CVE-2015-3989?
CVE-2015-3989 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2015-3989?
To fix CVE-2015-3989, it is recommended to upgrade Concrete5 to version 5.7.4 or later.
3
What are the potential impacts of CVE-2015-3989?
The potential impacts of CVE-2015-3989 include the injection of arbitrary web scripts or HTML, leading to data theft or session hijacking.
4
Which versions of Concrete5 are affected by CVE-2015-3989?
CVE-2015-3989 affects Concrete5 versions prior to 5.7.4.
5
Can CVE-2015-3989 be exploited remotely?
Yes, CVE-2015-3989 can be exploited remotely, allowing attackers to execute scripts in the context of a user's browser.