CVE-2017-5963
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy/Resources/Public/JavaScript/e-payment/paymill/api/php/payment.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
Se descubrió un problema en caddy (para TYPO3) en versiones anteriores a 7.2.10. La vulnerabilidad existe debido a la filtración insuficiente de datos suministrados por el usuario en el parámetro "paymillToken" de HTTP POST pasado a la URL "caddy/Resources/Public/JavaScript/e-payment/paymill/api/php/payment.php". Un atacante podría ejecutar código HTML y secuencias de comandos en un navegador en el contexto del sitio web vulnerable.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-02-11 CVE Reserved
- 2017-02-12 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/96198 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://forge.typo3.org/issues/79325 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 2.1.4 Search vendor "Caddy Project" for product "Caddy" and version "2.1.4" | alpha, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 2.1.5 Search vendor "Caddy Project" for product "Caddy" and version "2.1.5" | alpha, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 2.1.6 Search vendor "Caddy Project" for product "Caddy" and version "2.1.6" | alpha, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 3.0.0 Search vendor "Caddy Project" for product "Caddy" and version "3.0.0" | alpha, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 4.0.0 Search vendor "Caddy Project" for product "Caddy" and version "4.0.0" | alpha, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 4.0.1 Search vendor "Caddy Project" for product "Caddy" and version "4.0.1" | alpha, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 4.0.2 Search vendor "Caddy Project" for product "Caddy" and version "4.0.2" | alpha, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 4.0.3 Search vendor "Caddy Project" for product "Caddy" and version "4.0.3" | alpha, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 4.0.12 Search vendor "Caddy Project" for product "Caddy" and version "4.0.12" | alpha, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 6.0.1 Search vendor "Caddy Project" for product "Caddy" and version "6.0.1" | alpha, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 6.0.2 Search vendor "Caddy Project" for product "Caddy" and version "6.0.2" | alpha, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 6.0.9 Search vendor "Caddy Project" for product "Caddy" and version "6.0.9" | alpha, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 6.0.12 Search vendor "Caddy Project" for product "Caddy" and version "6.0.12" | beta, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 6.0.14 Search vendor "Caddy Project" for product "Caddy" and version "6.0.14" | beta, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 6.1.0 Search vendor "Caddy Project" for product "Caddy" and version "6.1.0" | beta, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 6.2.1 Search vendor "Caddy Project" for product "Caddy" and version "6.2.1" | beta, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 6.3.0 Search vendor "Caddy Project" for product "Caddy" and version "6.3.0" | beta, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 6.3.1 Search vendor "Caddy Project" for product "Caddy" and version "6.3.1" | beta, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 6.3.3 Search vendor "Caddy Project" for product "Caddy" and version "6.3.3" | beta, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 7.0.0 Search vendor "Caddy Project" for product "Caddy" and version "7.0.0" | beta, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 7.1.0 Search vendor "Caddy Project" for product "Caddy" and version "7.1.0" | beta, typo3 |
Affected
| ||||||
Caddy Project Search vendor "Caddy Project" | Caddy Search vendor "Caddy Project" for product "Caddy" | 7.2.7 Search vendor "Caddy Project" for product "Caddy" and version "7.2.7" | beta, typo3 |
Affected
|