CVE-2015-9286: XSS
Published Apr 30, 2019
·Updated
Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.
Affected Software
1 affected component
nodebb Nodebb<0.7.3
Remediation
Patch Available
Event History
Apr 30, 2019
CVE Published
via MITRE·01:07 PM
Data Sourced
via MITRE·01:07 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2015-9286.
2
What is the severity of CVE-2015-9286?
The severity of CVE-2015-9286 is medium with a severity value of 6.1.
3
What is the affected software for CVE-2015-9286?
The affected software for CVE-2015-9286 is NodeBB before version 0.7.3.
4
What is the CWE for CVE-2015-9286?
The CWE for CVE-2015-9286 is CWE-79 (Cross-Site Scripting).
5
How can I fix the XSS vulnerability in NodeBB before version 0.7.3?
To fix the XSS vulnerability in NodeBB before version 0.7.3, you should update to version 0.7.3 or later.