CVE-2015-8795
MEDIUMApache Solr < 5.0 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related to webapp/web/js/scripts/analysis.js or (2) Schema-Browser page, related to webapp/web/js/scripts/schema-browser.js.
Scores
CVSS v3
6.1
EPSS
0.0256
EPSS Percentile
85.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
draft
Affected Products (2)
apache/solr
< 5.0
org.apache.solr/solr-core
< 5.1.0Maven
Timeline
Published
Feb 15, 2016
Tracked Since
Feb 18, 2026