CVE-2016-4847
MEDIUMOssec Web UI < 0.8 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web script or HTML by leveraging an unanchored regex.
References (4)
Scores
CVSS v3
6.1
EPSS
0.0051
EPSS Percentile
66.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (2)
ossec/web_ui
< 0.8
n/a/n/a
Timeline
Published
Apr 20, 2017
Tracked Since
Feb 18, 2026