CVE-2015-3988 — Cross-site Scripting in Horizon
Severity
3.5LOWNVD
EPSS
0.4%
top 42.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 19
Latest updateMay 17
Description
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavor or (3) Host Aggregate.
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9
Affected Packages2 packages
🔴Vulnerability Details
3GHSA▶
GHSA-chfp-7692-g532: Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015↗2022-05-17
OSV▶
CVE-2015-3988: Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015↗2015-05-19
CVEList▶
CVE-2015-3988: Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015↗2015-05-19