CVE-2015-1864
medium
CVSS v3
5.4
CVSS v2
3.5
VIR risk
5.4
Description
Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name user details, or the (3) repository, (4) repository group, or (5) user group description.
Predictions
Exploit likelihood
64%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — https://kallithea-scm.org/security/cve-2015-1864.html
Vendor advisory: secalert@redhat.com — https://kallithea-scm.org/repos/kallithea/changeset/a8f2986afc18c9221bf99f88b06e60ab83c86c55
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| PyPI | kallithea | <0.2.1 | 0.2.1 |
References
- http://www.openwall.com/lists/oss-security/2015/04/14/12
- http://www.securityfocus.com/bid/74184
- https://kallithea-scm.org/repos/kallithea/changeset/a8f2986afc18c9221bf99f88b06e60ab83c86c55
- https://kallithea-scm.org/security/cve-2015-1864.html
- https://nvd.nist.gov/vuln/detail/CVE-2015-1864
- https://github.com/msabramo/kallithea
- https://github.com/pypa/advisory-database/tree/main/vulns/kallithea/PYSEC-2017-17.yaml
- https://web.archive.org/web/20200228161446/http://www.securityfocus.com/bid/74184
CWEs
CWE-79
Verify integrity in audit chain (admin only). AS-IS.