Medium severity6.1NVD Advisory· Published Oct 24, 2017· Updated May 13, 2026
CVE-2017-15878
CVE-2017-15878
Description
A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us feature.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
keystonenpm | < 4.0.0 | 4.0.0 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- github.com/keystonejs/keystone/pull/4478nvdIssue TrackingPatchThird Party AdvisoryWEB
- packetstormsecurity.com/files/144756/KeystoneJS-4.0.0-beta.5-Unauthenticated-Stored-Cross-Site-Scripting.htmlnvdExploitIssue TrackingPatchThird Party AdvisoryVDB EntryWEB
- www.exploit-db.com/exploits/43054/nvdExploitIssue TrackingPatchThird Party AdvisoryVDB Entry
- blog.securelayer7.net/keystonejs-open-source-penetration-testing-report/nvdIssue TrackingThird Party Advisory
- www.securityfocus.com/bid/101541nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-7qcx-jmrc-h2rrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-15878ghsaADVISORY
- blog.securelayer7.net/keystonejs-open-source-penetration-testing-reportghsaWEB
- securelayer7.net/download/pdf/KeystoneJS-Pentest-Report-SecureLayer7.pdfghsaWEB
- www.exploit-db.com/exploits/43054ghsaWEB
- www.npmjs.com/advisories/980ghsaWEB
News mentions
0No linked articles in our index yet.