CVE-2015-0931

EUVD-2015-0939
Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attackers to execute arbitrary code via a crafted XSLT document, related to a "resource injection" issue.
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
ektronektron_content_management_system
8.5.0
ektronektron_content_management_system
8.7.0
ektronektron_content_management_system
8.7.0:sp1
ektronektron_content_management_system
8.9.0
𝑥
= Vulnerable software versions