Medium severity6.1NVD Advisory· Published Oct 11, 2017· Updated Jun 17, 2026
CVE-2017-15215
CVE-2017-15215
Description
Reflected XSS vulnerability in Shaarli v0.9.1 allows an unauthenticated attacker to inject JavaScript via the searchtags parameter to index.php. If the victim is an administrator, an attacker can (for example) take over the admin session or change global settings or add/delete links. It is also possible to execute JavaScript against unauthenticated users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- openwall.com/lists/oss-security/2017/10/07/2nvdMailing ListPatchThird Party AdvisoryVDB Entry
- github.com/shaarli/Shaarli/pull/987nvdThird Party Advisory
- github.com/shaarli/Shaarli/releases/tag/v0.9.2nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.