CVE-2016-10515: XSS
Published Oct 18, 2017
·Updated
In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages.
Affected Software
1 affected component
Redmine Redmine<=3.2.2
Remediation
Event History
Oct 18, 2017
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10515?
CVE-2016-10515 is considered a moderate severity vulnerability due to its potential for stored XSS attacks.
2
How do I fix CVE-2016-10515?
To fix CVE-2016-10515, you should upgrade Redmine to version 3.2.3 or later.
3
What types of vulnerabilities are associated with CVE-2016-10515?
CVE-2016-10515 is associated with stored cross-site scripting (XSS) vulnerabilities in Textile and Markdown text formatting.
4
Which versions of Redmine are affected by CVE-2016-10515?
CVE-2016-10515 affects all Redmine versions prior to 3.2.3, specifically those up to version 3.2.2.
5
Where can I find more information about CVE-2016-10515?
You can find more information about CVE-2016-10515 in the Redmine security advisories.