4.3
CVSSv2

CVE-2015-5215

Published: 17/02/2020 Updated: 11/04/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The default configuration of the Jinja templating engine used in the Identity Provider (IdP) server in Ipsilon 0.1.0 prior to 1.0.1 does not enable auto-escaping, which makes it easier for remote malicious users to conduct cross-site scripting (XSS) attacks via template variables. NOTE: This may be a duplicate of CVE-2015-5216. Moreover, the Jinja development team does not enable auto-escape by default for performance issues as explained in jinja.palletsprojects.com/en/master/faq/#why-is-autoescaping-not-the-default.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ipsilon-project ipsilon

Vendor Advisories

Impact: Moderate Public Date: 2015-08-19 CWE: CWE-79 Bugzilla: 1255168: CVE-2015-5215 ipsilon: XSS in m ...