VYPR
Medium severity6.1NVD Advisory· Published Oct 11, 2017· Updated Jun 17, 2026

CVE-2017-15215

CVE-2017-15215

Description

Reflected XSS vulnerability in Shaarli v0.9.1 allows an unauthenticated attacker to inject JavaScript via the searchtags parameter to index.php. If the victim is an administrator, an attacker can (for example) take over the admin session or change global settings or add/delete links. It is also possible to execute JavaScript against unauthenticated users.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Shaarli/Shaarli2 versions
    cpe:2.3:a:shaarli_project:shaarli:0.9.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:shaarli_project:shaarli:0.9.1:*:*:*:*:*:*:*
    • (no CPE)range: <0.9.2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.