Cross-Site Scripting Vulnerability in PowerDNS Recursor by OpenDNS
CVE-2017-15092

6.1MEDIUM

Key Information:

Vendor
Powerdns
Vendor
CVE Published:
23 January 2018

Summary

A cross-site scripting vulnerability exists in the web interface of PowerDNS Recursor versions 4.0.0 through 4.0.6. This flaw allows a remote attacker to exploit the improperly handled display of the 'qname' of DNS queries, enabling the injection of malicious HTML and JavaScript code. As a result, an attacker could manipulate the user interface, potentially compromising the integrity of the application and affecting the users interacting with it.

Affected Version(s)

PowerDNS Recursor from 4.0.0 up to and including 4.0.6

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.