debian · CVE-2017-15215

Quick triage

Priority: unimportant Published: Updated: Tue, 23 Jun 2026 11:59:54 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-15215 unimportant priority: Debian including 1 source packages (shaarli), 3 status rows across 3 suites (bookworm, sid, trixie): resolved 3.

Description:

Reflected XSS vulnerability in Shaarli v0.9.1 allows an unauthenticated attacker to inject JavaScript via the searchtags parameter to index.php. If the victim is an administrator, an attacker can (for example) take over the admin session or change global settings or add/delete links. It is also possible to execute JavaScript against unauthenticated users.

cvelogic Threat Intelligence