Vulnerability Description
services/system_io/actionprocessor/Contact.rails in ConnectWise Manage 2017.5 allows arbitrary client-side JavaScript code execution (involving a ContactCommon field) on victims who click on a crafted link, aka XSS.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Connectwise | Manage | 2017.5 |
Related Weaknesses (CWE)
References
- https://becomepentester.blogspot.in/2017/07/ConnectWise-Manage-XSS-CVE-2017-1172ExploitThird Party Advisory
- https://becomepentester.blogspot.in/2017/07/ConnectWise-Manage-XSS-CVE-2017-1172ExploitThird Party Advisory
FAQ
What is CVE-2017-11727?
CVE-2017-11727 is a vulnerability with a CVSS score of 6.1 (MEDIUM). services/system_io/actionprocessor/Contact.rails in ConnectWise Manage 2017.5 allows arbitrary client-side JavaScript code execution (involving a ContactCommon field) on victims who click on a crafted...
How severe is CVE-2017-11727?
CVE-2017-11727 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-11727?
Check the references section above for vendor advisories and patch information. Affected products include: Connectwise Manage.