CVE-2017-15568 Vulnerability Details 
                
					
						
						   
					    /   
					
					
						
						   
					    /   
					
					
						
						   
					    /   
					
					
						
						   
					 
					
					
CVE-2017-15568 Metadata Quick Info 
					CVE Published: 18/10/2017  | 
					
CVE Updated: 05/08/2024  | 
					
CVE Year: 2017  
					
					Source:  mitre  | 
					
Vendor:  n/a  | 
					
Product: n/a  
					
					
					Status : PUBLISHED  
					
 
					CVE-2017-15568 Description 
					 
					In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of issue history.					
					
					
Metrics 
					CVSS Version: 3.1  | 
					
Base Score: n/a  
					Vector: n/a  
					
					l➤ Exploitability Metrics:      Attack Vector (AV)*        Attack Complexity (AC)*        Privileges Required (PR)*        User Interaction (UI)*        Scope (S)*   l➤ Impact Metrics:      Confidentiality Impact (C)*        Integrity Impact (I)*        Availability Impact (A)*   Weakness Enumeration (CWE) 
					CWE-ID:   CWE Name: n/a  Source: n/a  Common Attack Pattern Enumeration and Classification (CAPEC) 
					CAPEC-ID:   CAPEC Description:   
						Source: NVD (National Vulnerability Database).