AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-0862

LOW · CVSS 3.5 EPSS 1.15%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-01-18 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2015-0862
Severity
LOW
CVSS
3.5
EPSS
1.15%

Original NVD Description

Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in the RabbitMQ management plugin before 3.4.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) message details when a message is unqueued, such as headers or arguments; (2) policy names, which are not properly handled when viewing policies; (3) details for AMQP network clients, such as the version; allow remote authenticated administrators to inject arbitrary web script or HTML via (4) user names, (5) the cluster name; or allow RabbitMQ cluster administrators to (6) modify unspecified content.