Cross-Site Scripting Vulnerability in PowerDNS Recursor by OpenDNS
CVE-2017-15092
6.1MEDIUM
What is CVE-2017-15092?
A cross-site scripting vulnerability exists in the web interface of PowerDNS Recursor versions 4.0.0 through 4.0.6. This flaw allows a remote attacker to exploit the improperly handled display of the 'qname' of DNS queries, enabling the injection of malicious HTML and JavaScript code. As a result, an attacker could manipulate the user interface, potentially compromising the integrity of the application and affecting the users interacting with it.
Affected Version(s)
PowerDNS Recursor from 4.0.0 up to and including 4.0.6
