Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1) Assist plugin before 1.1.2.test20160906, (2) dataBox plugin before 0.0.0.20160906, and (3) userBox plugin before 0.0.0.20160906 for Geeklog allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References
Link | Resource |
---|---|
http://jvn.jp/en/jp/JVN46087986/index.html | Third Party Advisory VDB Entry |
http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000167.html | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/93123 | Third Party Advisory VDB Entry |
https://github.com/ivywe/geeklog-ivywe/commit/3cdb4ebca5746ff1e02b7e434d5722044d1d09d1 | Patch Third Party Advisory |
https://github.com/ivywe/geeklog-ivywe/commit/fe20a1bccdfec96125ab3d8dbee6ccbd0767c0be | Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2017-04-14 18:59
Updated : 2024-02-04 19:11
NVD link : CVE-2016-4875
Mitre link : CVE-2016-4875
CVE.ORG link : CVE-2016-4875
JSON object : View
Products Affected
databox_project
- databox_plugin
userbox_project
- userbox_plugin
assist_project
- assist_plugin
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')