Cross-Site Scripting Vulnerability in PowerDNS Recursor by OpenDNS
CVE-2017-15092
6.1MEDIUM
Summary
A cross-site scripting vulnerability exists in the web interface of PowerDNS Recursor versions 4.0.0 through 4.0.6. This flaw allows a remote attacker to exploit the improperly handled display of the 'qname' of DNS queries, enabling the injection of malicious HTML and JavaScript code. As a result, an attacker could manipulate the user interface, potentially compromising the integrity of the application and affecting the users interacting with it.
Affected Version(s)
PowerDNS Recursor from 4.0.0 up to and including 4.0.6
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved