First published: Fri Sep 11 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers to inject arbitrary web script or HTML via the scripts parameter to media/unit_testing/templates/6776.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/datatables/datatables | <1.10.10 | 1.10.10 |
npm/datatables | <1.10.10 | 1.10.10 |
Sprymedia DataTables | <=1.10.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6584 is classified as a high severity cross-site scripting (XSS) vulnerability.
To fix CVE-2015-6584, upgrade the DataTables plugin to version 1.10.10 or later.
CVE-2015-6584 affects versions of the DataTables plugin up to and including 1.10.8 for jQuery.
CVE-2015-6584 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts.
Yes, CVE-2015-6584 can compromise your website's security by allowing attackers to execute malicious scripts.