CVE-2017-15736: XSS
Cross-site scripting (XSS) vulnerability (stored) in SPIP before 3.1.7 allows remote attackers to inject arbitrary web script or HTML via a crafted string, as demonstrated by a PGP field, related to prive/objets/contenu/auteur.html and ecrire/inc/textemini.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-15736?
CVE-2017-15736 is a cross-site scripting (XSS) vulnerability (stored) in SPIP before 3.1.7 that allows remote attackers to inject arbitrary web script or HTML via a crafted string.
How does CVE-2017-15736 affect SPIP?
CVE-2017-15736 affects SPIP versions before 3.1.7.
What is the severity of CVE-2017-15736?
CVE-2017-15736 has a severity rating of 6.1 (high).
How can I fix CVE-2017-15736?
To fix CVE-2017-15736, you should update SPIP to version 3.1.7 or later.
Where can I find more information about CVE-2017-15736?
You can find more information about CVE-2017-15736 at the following references: - [https://core.spip.net/projects/spip/repository/revisions/23701](https://core.spip.net/projects/spip/repository/revisions/23701) - [https://www.debian.org/security/2018/dsa-4228](https://www.debian.org/security/2018/dsa-4228) - [https://usn.ubuntu.com/4536-1/](https://usn.ubuntu.com/4536-1/)