6.1
CVSSv3

CVE-2017-15878

Published: 24/10/2017 Updated: 14/11/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS prior to 4.0.0-beta.7 via the Contact Us feature.

Vulnerable Product Search on Vulmon Subscribe to Product

keystonejs keystone

Exploits

# Exploit Title: KeystoneJS 400-beta5 Unauthenticated Stored XSS # Vendor Homepage: keystonejscom/ # Exploit Author: Ishaq Mohammed # Contact: twittercom/security_prince # Website: aboutme/security-prince # Category: WEBAPPS # Platform: Nodejs # CVE: CVE-2017-15878 Vendor Description: KeystoneJS is a powerful Nodejs ...
KeystoneJS version 400-beta5 suffers from an unauthenticated stored cross site scripting vulnerability ...