CVE-2017-15881: XSS
Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web script or HTML via the "content brief" or "content extended" field, a different vulnerability than CVE-2017-15878.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15881?
CVE-2017-15881 has been classified as a high severity vulnerability due to the potential for remote authenticated administrators to inject arbitrary web scripts or HTML.
How do I fix CVE-2017-15881?
To fix CVE-2017-15881, upgrade KeystoneJS to version 4.0.0-beta.7 or later.
What type of vulnerability is CVE-2017-15881?
CVE-2017-15881 is identified as a Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2017-15881?
CVE-2017-15881 affects remote authenticated administrators using KeystoneJS versions prior to 4.0.0-beta.7.
What are the potential consequences of CVE-2017-15881?
The potential consequences of CVE-2017-15881 include unauthorized script execution and possible compromise of user data.