CVE-2015-7711: XSS
Published Aug 31, 2017
·Updated
Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the h parameter.
Affected Software
1 affected component
ATutor ATutor<=2.2
Event History
Aug 31, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7711?
The severity of CVE-2015-7711 is categorized as medium due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2015-7711?
To fix CVE-2015-7711, update ATutor to version 2.2.1 or later, which addresses the XSS vulnerability.
3
Who is affected by CVE-2015-7711?
CVE-2015-7711 affects users of ATutor version 2.2 and earlier.
4
What are the potential impacts of CVE-2015-7711?
The potential impacts of CVE-2015-7711 include unauthorized script execution and data theft through cross-site scripting.
5
Can CVE-2015-7711 be exploited remotely?
Yes, CVE-2015-7711 can be exploited remotely by attackers injecting arbitrary scripts via the h parameter.