CVE-2016-15008

A vulnerability was found in oxguy3 coebot-www and classified as problematic. This issue affects the function displayChannelCommands/displayChannelQuotes/displayChannelAutoreplies/showChannelHighlights/showChannelBoir of the file js/channel.js. The manipulation leads to cross site scripting. The attack may be initiated remotely. The patch is named c1a6c44092585da4236237e0e7da94ee2996a0ca. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217355.
Configurations

Configuration 1 (hide)

cpe:2.3:a:coebot-www_project:coebot-www:*:*:*:*:*:coebot:*:*

History

21 Nov 2024, 02:45

Type Values Removed Values Added
References () https://github.com/oxguy3/coebot-www/commit/c1a6c44092585da4236237e0e7da94ee2996a0ca - Patch, Third Party Advisory () https://github.com/oxguy3/coebot-www/commit/c1a6c44092585da4236237e0e7da94ee2996a0ca - Patch, Third Party Advisory
References () https://vuldb.com/?ctiid.217355 - Third Party Advisory () https://vuldb.com/?ctiid.217355 - Third Party Advisory
References () https://vuldb.com/?id.217355 - Third Party Advisory () https://vuldb.com/?id.217355 - Third Party Advisory
CVSS v2 : 4.0
v3 : 6.1
v2 : 4.0
v3 : 3.5

29 Feb 2024, 01:17

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad fue encontrada en oxguy3 coebot-www y clasificada como problemática. Este problema afecta la función displayChannelCommands/displayChannelQuotes/displayChannelAutoreplies/showChannelHighlights/showChannelBoir del archivo js/channel.js. La manipulación conduce a cross site scripting. El ataque puede iniciarse de forma remota. El parche se llama c1a6c44092585da4236237e0e7da94ee2996a0ca. Se recomienda aplicar un parche para solucionar este problema. El identificador asociado de esta vulnerabilidad es VDB-217355.

Information

Published : 2023-01-04 10:15

Updated : 2024-11-21 02:45


NVD link : CVE-2016-15008

Mitre link : CVE-2016-15008

CVE.ORG link : CVE-2016-15008


JSON object : View

Products Affected

coebot-www_project

  • coebot-www
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')