Vulnerability Description
Cross-site scripting (XSS) vulnerability in js/ViewerPanel.js in the file previewer plugin in Kopano WebApp versions 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a specially crafted previewable file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kopano | Webapp | <= 3.3.0 |
Related Weaknesses (CWE)
References
- https://stash.kopano.io/projects/KWA/repos/filepreviewer/commits/85d2b5c2d27f461Third Party Advisory
- https://stash.kopano.io/projects/KWA/repos/filepreviewer/commits/85d2b5c2d27f461Third Party Advisory
FAQ
What is CVE-2017-11666?
CVE-2017-11666 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross-site scripting (XSS) vulnerability in js/ViewerPanel.js in the file previewer plugin in Kopano WebApp versions 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML vi...
How severe is CVE-2017-11666?
CVE-2017-11666 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-11666?
Check the references section above for vendor advisories and patch information. Affected products include: Kopano Webapp.