MEDIUM
admont28 Ingnovarq insertarSliderAjax.php cross site scripting
Published Jan 1, 2023
6.1
MEDIUMCVSS 3.1
EPSS 0.52%
Description
A vulnerability, which was classified as problematic, has been found in admont28 Ingnovarq. Affected by this issue is some unknown functionality of the file app/controller/insertarSliderAjax.php. The manipulation of the argument imagetitle leads to cross site scripting. The attack may be launched remotely. The name of the patch is 9d18a39944d79dfedacd754a742df38f99d3c0e2. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217172.
Affected products
-
Affected
- n/a
- < 2015-02-04
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2015-1025 Advisory
- https://github.com/admont28/ingnovarq/commit/9d18a39944d79dfedacd754a742df38f99d3c0e2 patchThird Party Advisory
- https://vuldb.com/?ctiid.217172 signaturepermissions-requiredThird Party Advisory
- https://vuldb.com/?id.217172 vdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2015-1025 | Advisory | |
| https://github.com/admont28/ingnovarq/commit/9d18a39944d79dfedacd754a742df38f99d3c0e2 | patchThird Party Advisory | |
| https://vuldb.com/?ctiid.217172 | signaturepermissions-requiredThird Party Advisory | |
| https://vuldb.com/?id.217172 | vdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jan 1, 2023
Updated Apr 10, 2025
Reserved Jan 1, 2023
Link CVE-2015-10006
CISA Vulnrichment
Updated Apr 10, 2025
Red Hat
No data
GitHub
No data