First published: Fri Mar 03 2017(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Umbraco before 7.4.0 allow remote attackers to inject arbitrary web script or HTML via the name parameter to (1) the media page, (2) the developer data edit page, or (3) the form page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Umbraco CMS | <=7.3.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8815 is classified as a medium severity vulnerability due to its potential for exploiting multiple cross-site scripting (XSS) scenarios.
To fix CVE-2015-8815, upgrade your Umbraco CMS to version 7.4.0 or later.
CVE-2015-8815 includes multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web scripts or HTML.
Umbraco versions before 7.4.0, specifically up to 7.3.8, are affected by CVE-2015-8815.
The attack vectors for CVE-2015-8815 include the media page, developer data edit page, and form page.