CVE-2015-7383: Refbase
Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.
Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge through 2015-04-28 allow remote attackers to inject arbitrary web script or HTML via the (1) adminUserName, (2) pathToMYSQL, (3) databaseStructureFile, or (4) pathToBibutils parameter to install.php or the (5) adminUserName parameter to update.php.
Affected products
- Refbase Refbase: up to and including 0.9.6
Published 2015-09-28. Last modified 2026-06-17.