First published: Mon Apr 11 2016(Updated: )
Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the event description when creating an event.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache OpenMeetings | <=3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2163 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2016-2163, upgrade Apache OpenMeetings to version 3.1.1 or later.
CVE-2016-2163 allows remote attackers to inject arbitrary web scripts or HTML into event descriptions, potentially compromising users' security.
CVE-2016-2163 affects all versions of Apache OpenMeetings prior to 3.1.1.
Yes, CVE-2016-2163 can be exploited without user interaction if an attacker manipulates an event description that a victim accesses.