CVE-2016-7149: XSS
Published Jan 18, 2017
·Updated
Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to the autolink function.
Affected Software
1 affected component
b2evolution b2evolution<=6.7.5
Remediation
Patch Available
Patch Available
Event History
Jan 18, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7149?
CVE-2016-7149 has a medium severity rating due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2016-7149?
To fix CVE-2016-7149, update b2evolution to version 6.7.6 or later, where the vulnerability has been addressed.
3
What software versions are affected by CVE-2016-7149?
CVE-2016-7149 affects b2evolution versions 6.7.5 and earlier.
4
What type of attack does CVE-2016-7149 enable?
CVE-2016-7149 enables remote attackers to perform cross-site scripting (XSS) attacks.
5
Is my website at risk if I use b2evolution version 6.7.5 or earlier?
Yes, if you use b2evolution version 6.7.5 or earlier, your website is at risk due to CVE-2016-7149.