First published: Thu Apr 20 2017(Updated: )
Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web script or HTML by leveraging an unanchored regex.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
OSSEC | <=0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4847 is classified as a medium severity cross-site scripting vulnerability.
To fix CVE-2016-4847, update the OSSEC Web UI to version 0.9 or later.
CVE-2016-4847 enables remote attackers to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML.
CVE-2016-4847 affects the OSSEC Web UI versions prior to 0.9.
For more detailed information, refer to the official CVE database or vulnerability advisory sites.