First published: Mon Feb 15 2016(Updated: )
Cross-site scripting (XSS) vulnerability in `webapp/web/js/scripts/schema-browser.js` in the Admin UI in Apache Solr before 5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted schema-browse URL.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Solr | <=5.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8796 is classified as a moderate severity vulnerability due to its potential for cross-site scripting (XSS) exploitation.
To mitigate CVE-2015-8796, upgrade Apache Solr to version 5.3 or later.
CVE-2015-8796 affects Apache Solr versions prior to 5.3, specifically the Admin UI component.
Attackers can exploit CVE-2015-8796 to inject arbitrary web scripts or HTML into affected systems.
Yes, CVE-2015-8796 specifically affects the schema-browser JavaScript file within the Admin UI.