Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15928

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 7.4

Описание

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.

A flaw was found in the XMLRPC-C Library. This reflected cross-site scripting (XSS) vulnerability exists in the error page component. A remote attacker could exploit this by tricking a user into clicking a specially crafted link. Successful exploitation could lead to the execution of malicious scripts in the user's browser, potentially resulting in information disclosure or session hijacking.

Отчет

This reflected cross-site scripting (XSS) vulnerability relies entirely on client-side interaction through a web browser. Practical exploitation requires a remote attacker to trick a user into clicking a targeted link that passes crafted input to an application displaying the XMLRPC-C error page. If executed, the script runs within the context of the user's browser session, making sensitive session tokens or client-side data accessible to the attacker. While external CVSSv4 scoring rates this flaw to an 8.2 High, Red Hat bounds the severity to CVSS 7.4 based on explicit CIA triad mechanics. The impact is strictly confined to Confidentiality (C:H) via potential browser-side data disclosure. The flaw carries zero impact on system Integrity (I:N) or Availability (A:N), as it cannot alter server-side application logic, modify stored data, or disrupt underlying XML-RPC services. Deployments operating strictly as headless backend services, non-interactive daemons, or server-to-server API endpoints—where the XMLRPC-C error component is never exposed or rendered inside a user's web browser—are fundamentally outside the execution boundary of this flaw and remain at zero risk.

Меры по смягчению последствий

To mitigate this issue, ensure that applications utilizing the XMLRPC-C library do not directly expose its error pages to end-users via a web browser. Configure web servers or application frontends to intercept and sanitize or replace error responses originating from XMLRPC-C before they are rendered client-side. Alternatively, restrict XMLRPC-C deployments to backend services that do not present error output in a user-facing web interface.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xmlrpc-cOut of support scope
Red Hat Enterprise Linux 7xmlrpc-cAffected
Red Hat Enterprise Linux 8xmlrpc-cAffected
Red Hat Enterprise Linux 9xmlrpc-cAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2507394xmlrpc-c: XMLRPC-C Library: Cross-Site Scripting in error page component

7.4 High

CVSS3

Связанные уязвимости

ubuntu
22 дня назад

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.

nvd
22 дня назад

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.

debian
22 дня назад

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a ref ...

suse-cvrf
7 дней назад

Security update for xmlrpc-c

github
22 дня назад

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.

7.4 High

CVSS3