Overview
SearchBlox versions 8.1.x and below contain multiple vulnerabilities.
Description
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') - CVE-2015-0967 SearchBlox contains multiple cross-site scripting (XSS) vulnerabilities, including a reflected XSS in the default search box of http://<HOST_NAME>:8080/searchblox/plugin/index.html and a persistent XSS in the title field of the 'Create Featured Result' form, http://<HOST_NAME>:8080/searchblox/admin/main.jsp?menu1=res. Note that an attacker must be authenticated to leverage the persistent XSS. |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary script in the contexts of the end-user's browser session, the application, or an authenticated user. Sensitive information may be exposed to unauthenticated users. |
Solution
Apply an update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Temporal | 6.2 | E:F/RL:OF/RC:C |
Environmental | 5.5 | CDP:LM/TD:M/CR:M/IR:M/AR:M |
References
Acknowledgements
Thanks to Ashish Kamble of Qualys for reporting this vulnerability.
This document was written by Joel Land.
Other Information
CVE IDs: | CVE-2015-0967, CVE-2015-0968, CVE-2015-0969, CVE-2015-0970 |
Date Public: | 2015-04-14 |
Date First Published: | 2015-04-14 |
Date Last Updated: | 2015-04-14 13:59 UTC |
Document Revision: | 14 |