Cross-Site Scripting Vulnerability in PowerDNS Recursor by OpenDNS
CVE-2017-15092
6.1MEDIUM
What is CVE-2017-15092?
A cross-site scripting vulnerability exists in the web interface of PowerDNS Recursor versions 4.0.0 through 4.0.6. This flaw allows a remote attacker to exploit the improperly handled display of the 'qname' of DNS queries, enabling the injection of malicious HTML and JavaScript code. As a result, an attacker could manipulate the user interface, potentially compromising the integrity of the application and affecting the users interacting with it.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PowerDNS Recursor from 4.0.0 up to and including 4.0.6
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
