{"id":"CVE-2016-10510","details":"Cross-site scripting (XSS) vulnerability in the Security component of Kohana before 3.3.6 allows remote attackers to inject arbitrary web script or HTML by bypassing the strip_image_tags protection mechanism in system/classes/Kohana/Security.php.","modified":"2026-07-08T05:48:05.341076821Z","published":"2017-08-31T20:29:00.323Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"}]},"references":[{"type":"ADVISORY","url":"https://advisory.checkmarx.net/advisory/CX-2016-4451"},{"type":"ADVISORY","url":"https://github.com/kohana/kohana/releases/tag/v3.3.6"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/01/msg00015.html"},{"type":"FIX","url":"https://github.com/kohana/kohana/issues/107"},{"type":"EVIDENCE","url":"https://www.checkmarx.com/advisories/cross-site-scripting-xss-vulnerability-in-kohana/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kohana/kohana","events":[{"introduced":"0"},{"last_affected":"284024b4972f069dea7ceeacbd8be0ffa4a2dbcf"},{"fixed":"98674c63399c29c0fdb812c04c99dc1c6ca5aec8"}],"database_specific":{"cpe":"cpe:2.3:a:kohanaframework:kohana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.3.5"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v3.3.5","v3.3.4","v3.3.3.1","v3.3.3","v3.3.1.1","v3.3.1","v3.3.0","v3.2.0","v3.3.0-RC2","v3.3.0-RC1","v3.2.0-RC2","v3.2.0-RC1","v3.1.0","v3.1.0-RC2","3.1-RC1","3.0.7","3.0.6.2","3.0.6.1","3.0.6","3.0.5","3.0.4.2","3.0.4.1","3.0.4","3.0.3","3.0.2.1","3.0.2","3.0.1.2","3.0.1.1","3.0.1","3.0","3.0rc3","3.0rc2.1","3.0rc2","3.0rc1","beta3","beta2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10510.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}