CVE-2015-4673: XSS
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.7.0.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the collectiondescription parameter to upload/managecollections.php in an addnew action or the (2) photodescription, (3) phototags, or (4) phototitle parameter to upload/actions/photouploader.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4673?
CVE-2015-4673 is classified as a medium severity vulnerability due to the potential for user data manipulation.
How do I fix CVE-2015-4673?
To fix CVE-2015-4673, ensure you upgrade ClipBucket to the latest version that addresses these XSS vulnerabilities.
Who is affected by CVE-2015-4673?
CVE-2015-4673 affects remote authenticated users of ClipBucket version 2.7.0.5 who can exploit the cross-site scripting weaknesses.
What types of attacks can be conducted using CVE-2015-4673?
CVE-2015-4673 allows attackers to conduct cross-site scripting attacks that can lead to session hijacking or data theft.
Is CVE-2015-4673 being actively exploited?
There have been no confirmed reports of active exploitation of CVE-2015-4673, but it remains a potential risk for users depending on security practices.