CVE-2015-8815: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Umbraco before 7.4.0 allow remote attackers to inject arbitrary web script or HTML via the name parameter to (1) the media page, (2) the developer data edit page, or (3) the form page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8815?
CVE-2015-8815 is classified as a medium severity vulnerability due to its potential for exploiting multiple cross-site scripting (XSS) scenarios.
How do I fix CVE-2015-8815?
To fix CVE-2015-8815, upgrade your Umbraco CMS to version 7.4.0 or later.
What types of vulnerabilities does CVE-2015-8815 include?
CVE-2015-8815 includes multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web scripts or HTML.
Which versions of Umbraco are affected by CVE-2015-8815?
Umbraco versions before 7.4.0, specifically up to 7.3.8, are affected by CVE-2015-8815.
What are the attack vectors for CVE-2015-8815?
The attack vectors for CVE-2015-8815 include the media page, developer data edit page, and form page.