Vulnerability Description
interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are mishandled in the history page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rspamd Project | Rspamd | <= 1.6.2 |
Related Weaknesses (CWE)
References
- https://github.com/vstakhov/rspamd/issues/1738ExploitIssue TrackingThird Party Advisory
- https://github.com/vstakhov/rspamd/releases/tag/1.6.3Release NotesThird Party Advisory
- https://github.com/vstakhov/rspamd/issues/1738ExploitIssue TrackingThird Party Advisory
- https://github.com/vstakhov/rspamd/releases/tag/1.6.3Release NotesThird Party Advisory
FAQ
What is CVE-2017-11737?
CVE-2017-11737 is a vulnerability with a CVSS score of 6.1 (MEDIUM). interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are mishandled in the history page.
How severe is CVE-2017-11737?
CVE-2017-11737 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-11737?
Check the references section above for vendor advisories and patch information. Affected products include: Rspamd Project Rspamd.