CVE-2015-8477: XSS
Published May 23, 2017
·Updated
Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving flash message rendering.
Affected Software
1 affected component
Redmine Redmine<=2.6.1
Remediation
Patch Available
Event History
May 23, 2017
CVE Published
via MITRE·03:56 AM
Data Sourced
via MITRE·03:56 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8477?
CVE-2015-8477 has a medium severity level due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2015-8477?
To fix CVE-2015-8477, upgrade Redmine to version 2.6.2 or later.
3
What kind of attacks can CVE-2015-8477 enable?
CVE-2015-8477 allows attackers to inject arbitrary web scripts or HTML, leading to potential data theft or session hijacking.
4
Which versions of Redmine are affected by CVE-2015-8477?
Redmine versions prior to 2.6.2 are affected by CVE-2015-8477.
5
Is CVE-2015-8477 a newly discovered vulnerability?
CVE-2015-8477 was publicly disclosed in December 2015.