CVE-2014-8488

YOURLS 1.7 - Stored Cross-Site Scripting via Shorten Functionality

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the administrator panel in Yourls 1.7 allows remote attackers to inject arbitrary web script or HTML via a URL that is processed by the Shorten functionality.

References (4)

Core 4
Core References
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156596.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156526.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156564.html
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Oct/111

Scores

EPSS 0.0186
EPSS Percentile 77.1%

Details

CWE
CWE-79
Status published
Products (4)
fedoraproject/fedora 20
fedoraproject/fedora 21
fedoraproject/fedora 22
yourls/yourls 1.7
Published Dec 10, 2014
Tracked Since Feb 18, 2026