CVE-2015-8508: XSS
Cross-site scripting (XSS) vulnerability in showdependencygraph.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2, when a local dot configuration is used, allows remote attackers to inject arbitrary web script or HTML via a crafted bug summary.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8508?
CVE-2015-8508 is classified as a moderate severity Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2015-8508?
To fix CVE-2015-8508, upgrade Bugzilla to version 4.2.16 or later, or to 4.4.11 or later, or to 5.0.2 or later.
What versions of Bugzilla are affected by CVE-2015-8508?
CVE-2015-8508 affects Bugzilla versions 2.x, 3.x, and 4.x prior to 4.2.16, as well as versions 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2.
What type of vulnerability is CVE-2015-8508?
CVE-2015-8508 is a Cross-Site Scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
What is the impact of CVE-2015-8508?
The impact of CVE-2015-8508 can include the potential exposure of sensitive data or user sessions through the injection of malicious scripts.