CVE-2015-0967 describes multiple cross-site scripting (XSS) vulnerabilities in SearchBlox versions prior to 8.2. Attackers can inject malicious web scripts or HTML through the search field in plugin/index.html or the title field in the Create Featured Result form in admin/main.jsp. This vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and requiring no authentication, with a potential impact of information disclosure and unauthorized actions on the user's browser. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While community discussion and media coverage are limited, the vulnerability has been publicly disclosed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.1CPE matchmatch criteria | cpe:2.3:a:searchblox:searchblox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.