CVE-2015-8856: XSS
Cross-site scripting (XSS) vulnerability in the serve-index package before 1.6.3 for Node.js allows remote attackers to inject arbitrary web script or HTML via a crafted file or directory name.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8856?
CVE-2015-8856 has been classified with a moderate severity due to its potential for exploitation through cross-site scripting (XSS).
How do I fix CVE-2015-8856?
To fix CVE-2015-8856, you should upgrade the serve-index package to version 1.6.3 or later for Node.js.
What does CVE-2015-8856 allow an attacker to do?
CVE-2015-8856 allows an attacker to inject arbitrary web script or HTML via a crafted file or directory name.
Which versions of serve-index are affected by CVE-2015-8856?
CVE-2015-8856 affects all versions of the serve-index package prior to 1.6.3.
How can I determine if I am using a vulnerable version of serve-index related to CVE-2015-8856?
You can determine if you are using a vulnerable version of serve-index by checking the package version in your Node.js application against the affected version criteria.