CVE-2015-5667

low
Published 2015-10-31 · Modified 2026-05-06
CVSS v3
CVSS v2
2.6
VIR risk
2.6

Description

Cross-site scripting (XSS) vulnerability in the HTML-Scrubber module before 0.15 for Perl, when the comment feature is enabled, allows remote attackers to inject arbitrary web script or HTML via a crafted comment.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-5667

vendor Authored 2026-05-27

Vendor advisory: vultures@jpcert.or.jp — https://metacpan.org/release/HTML-Scrubber

vendor Authored 2026-05-27

Vendor advisory: vultures@jpcert.or.jp — http://jvndb.jvn.jp/jvndb/JVNDB-2015-000171

vendor Authored 2026-05-27

Vendor advisory: vultures@jpcert.or.jp — http://jvn.jp/en/jp/JVN53973084/index.html

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.15-1
debian debianbullseyefixed0.15-1
debian debianforkyfixed0.15-1
debian debiansidfixed0.15-1
debian debiantrixiefixed0.15-1

Application impact

VendorProductVersionsFixed
html-scrubber_projecthtml-scrubber{"endIncluding":"0.14"}

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.