CVE-2017-20061
Elefant CMS extended Reflected cross site scriting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been found in Elefant CMS 1.3.12-RC and classified as problematic. This vulnerability affects unknown code of the file /admin/extended. The manipulation of the argument name with the input %3Cimg%20src=no%20onerror=alert(1)%3E leads to basic cross site scripting (Reflected). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.
Se ha encontrado una vulnerabilidad en Elefant CMS versión 1.3.12-RC y ha sido clasificado como problemática. Esta vulnerabilidad afecta a código desconocido del archivo /admin/extended. La manipulación del nombre del argumento con el input %3Cimg%20src=no%20onerror=alert(1)%3E conlleva a un ataque de tipo cross site scripting básico (Reflejado). El ataque puede ser iniciado remotamente. La explotación ha sido revelada al público y puede ser usada. La actualización a versión 1.3.13 puede abordar este problema. Es recomendado actualizar el componente afectado
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-06-18 CVE Reserved
- 2022-06-20 CVE Published
- 2024-01-11 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2017/Feb/36 | Mailing List |
|
https://vuldb.com/?id.97258 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Elefantcms Search vendor "Elefantcms" | Elefant Cms Search vendor "Elefantcms" for product "Elefant Cms" | 1.3.12 Search vendor "Elefantcms" for product "Elefant Cms" and version "1.3.12" | rc |
Affected
|