CVE-2016-10515
published 2017-10-18CVE-2016-10515: In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages.
PriorityP423medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
0.68%
48.2th percentile
In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | redmine | < redmine 3.2.3-1 (bookworm) | redmine 3.2.3-1 (bookworm) |
| redmine | redmine | <= 3.2.2 | — |
| redmine | redmine | >= 0 < 3.2.3-1 | 3.2.3-1 |
| redmine | redmine | >= 0 < 3.2.3-1 | 3.2.3-1 |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2016-10515: redmine - In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile ...
vendor_debian·2016·CVSS 6.1
CVE-2016-10515 [MEDIUM] CVE-2016-10515: redmine - In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile ...
In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages.
Scope: local
bookworm: resolved (fixed in 3.2.3-1)
sid: resolved (fixed in 3.2.3-1)
trixie: resolved (fixed in 3.2.3-1)
GHSA
GHSA-r5hm-658v-6xj3: In Redmine before 3
ghsa_unreviewed·2022-05-17
CVE-2016-10515 [MEDIUM] CWE-79 GHSA-r5hm-658v-6xj3: In Redmine before 3
In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages.
OSV
CVE-2016-10515: In Redmine before 3
osv·2017-10-18·CVSS 6.1
CVE-2016-10515 [MEDIUM] CVE-2016-10515: In Redmine before 3
In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and project homepages.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-18
Published