CVE-2015-10080 describes a Cross-Site Scripting (XSS) vulnerability in NREL api-umbrella-web version 0.7.1, specifically within an unknown part of the Admin Data Table Handler component. This medium-severity vulnerability (CVSS 6.1) can be exploited remotely with low attack complexity, requiring user interaction, and could lead to limited confidentiality and integrity impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. Upgrading to version 0.8.0 or applying patch f53a9fb87e10c457f0f3dd4f2af24d3b2f21b3ca is recommended for remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.7.1CPE matchmatch criteria | cpe:2.3:a:nrel:api_umbrella:0.7.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.