CVE-2018-15917: XSS
Published Sep 5, 2018
·Updated
Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.
Affected Software
1 affected component
Jorani Project Jorani=0.6.5
Event History
Sep 5, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-15917?
CVE-2018-15917 is a vulnerability in Jorani 0.6.5 that allows remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.
2
How severe is CVE-2018-15917?
CVE-2018-15917 has a severity score of 5.4, which is considered medium.
3
How can remote attackers exploit CVE-2018-15917?
Remote attackers can exploit CVE-2018-15917 by injecting arbitrary web script or HTML through the language parameter to session/language.
4
What is the affected software version of CVE-2018-15917?
CVE-2018-15917 affects Jorani version 0.6.5.
5
Is there a fix available for CVE-2018-15917?
Yes, it is recommended to update Jorani to a version that is not affected by CVE-2018-15917.