CVE-2016-7150: XSS
Published Jan 18, 2017
·Updated
Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the site name.
Affected Software
1 affected component
b2evolution b2evolution<=6.7.5
Remediation
Patch Available
Patch Available
Event History
Jan 18, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7150?
CVE-2016-7150 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2016-7150?
To fix CVE-2016-7150, upgrade to b2evolution version 6.7.6 or later.
3
What is the impact of CVE-2016-7150?
CVE-2016-7150 allows remote authenticated users to inject arbitrary web script or HTML into the site name.
4
Who is affected by CVE-2016-7150?
CVE-2016-7150 affects b2evolution versions 6.7.5 and earlier.
5
What type of vulnerability is CVE-2016-7150?
CVE-2016-7150 is a cross-site scripting (XSS) vulnerability.