Powerdns · Powerdns Recursor · CVE-2017-15092
Name of the Vulnerable Software and Affected Versions:
PowerDNS Recursor versions 4.0.0 through 4.0.6
Description:
A cross-site scripting issue has been found in the web interface, where the qname of DNS queries was displayed without any escaping, allowing a remote attacker to inject HTML and Javascript code into the web interface, altering the content.
Recommendations:
For versions 4.0.0 through 4.0.6, update to a version that includes the fix for this issue to prevent cross-site scripting attacks.