CVE-2015-6176 describes a cross-site scripting (XSS) filter bypass vulnerability in Microsoft Edge, where the browser improperly handles HTML attributes in HTTP responses. This medium-severity vulnerability (CVSS 4.3) could allow a remote attacker to bypass XSS protection mechanisms, potentially leading to information disclosure (I:P) with no impact on confidentiality or availability. While there is an ExploitDB entry (EDB-52372) demonstrating XSS, there is no evidence of active exploitation, Metasploit or Nuclei modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.