CVE-2015-8795: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related to webapp/web/js/scripts/analysis.js or (2) Schema-Browser page, related to webapp/web/js/scripts/schema-browser.js.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8795?
CVE-2015-8795 is considered a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2015-8795?
To fix CVE-2015-8795, upgrade Apache Solr to version 5.1 or later, which addresses the XSS vulnerabilities.
What type of vulnerability is CVE-2015-8795?
CVE-2015-8795 is a multiple cross-site scripting (XSS) vulnerability affecting the Admin UI of Apache Solr.
Which versions of Apache Solr are affected by CVE-2015-8795?
CVE-2015-8795 affects Apache Solr versions prior to 5.1.
Can CVE-2015-8795 be exploited remotely?
Yes, CVE-2015-8795 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.