Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openid_identifier parameter in a verify action to ikiwiki.cgi.
| Software | From | Fixed in |
|---|---|---|
| ikiwiki / ikiwiki | - | 3.20150329 |
| fedoraproject / fedora | 22 | 22.x |
| fedoraproject / fedora | 20 | 20.x |
| fedoraproject / fedora | 21 | 21.x |