CVE-2015-10059

A vulnerability has been found in s134328 Webapplication-Veganguide and classified as problematic. This vulnerability affects unknown code of the file p05-integration/app/shared/api/apiService.js. The manipulation of the argument country/city leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 2aa760fa4e779e40a28206a32ac22ac10356f519. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218416.
References
Link Resource
https://github.com/s134328/Webapplication-Veganguide/commit/2aa760fa4e779e40a28206a32ac22ac10356f519 Patch Third Party Advisory
https://vuldb.com/?ctiid.218416 Third Party Advisory VDB Entry
https://vuldb.com/?id.218416 Permissions Required Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:webapplication-veganguide_project:webapplication-veganguide:*:*:*:*:*:*:*:*

History

11 Apr 2024, 00:53

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en s134328 Webapplication-Veganguide y se ha clasificado como problemática. Esta vulnerabilidad afecta a un código desconocido del archivo p05-integration/app/shared/api/apiService.js. La manipulación del argumento país/ciudad conduce a cross-site scripting. El ataque se puede iniciar de forma remota. El nombre del parche es 2aa760fa4e779e40a28206a32ac22ac10356f519. Se recomienda aplicar un parche para solucionar este problema. El identificador de esta vulnerabilidad es VDB-218416.

Information

Published : 2023-01-17 13:15

Updated : 2024-05-17 01:03


NVD link : CVE-2015-10059

Mitre link : CVE-2015-10059

CVE.ORG link : CVE-2015-10059


JSON object : View

Products Affected

webapplication-veganguide_project

  • webapplication-veganguide
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')