CVE-2016-7981: XSS
Published Jan 18, 2017
·Updated
Cross-site scripting (XSS) vulnerability in validerxml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the varurl parameter in a validerxml action.
Affected Software
1 affected component
Spip SPIP<=3.1.2
Remediation
Patch Available
Event History
Jan 18, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-7981?
CVE-2016-7981 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2016-7981?
To fix CVE-2016-7981, upgrade to SPIP version 3.1.3 or later.
3
What systems are affected by CVE-2016-7981?
CVE-2016-7981 affects SPIP versions 3.1.2 and earlier.
4
What type of vulnerability is CVE-2016-7981?
CVE-2016-7981 is a cross-site scripting (XSS) vulnerability.
5
How can CVE-2016-7981 be exploited?
Attackers can exploit CVE-2016-7981 by injecting arbitrary web scripts or HTML through the var_url parameter.