CVE-2017-15213: Flyspray
Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.
Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges, via the real_name or email_address field to themes/CleanFS/templates/common.editallusers.tpl.
Affected products
- Flyspray Flyspray: up to and including 1.0
Published 2017-10-11. Last modified 2026-06-17.