Vulnerability Description
IDenticard Two-Reader Controller Configuration Manager 1.18.8 (396) is vulnerable to Stored Cross-Site Scripting (XSS) via the notes field in /~user_handler?file=logged_in.shtm (aka the edit user page).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Identicard | Two-Reader Controller Configuration Manager | 1.18.8_\(396\) |
Related Weaknesses (CWE)
References
- https://raw.githubusercontent.com/badbiddy/Vulnerability-Disclosure/master/IDentThird Party Advisory
- https://raw.githubusercontent.com/badbiddy/Vulnerability-Disclosure/master/IDentThird Party Advisory
FAQ
What is CVE-2017-14973?
CVE-2017-14973 is a vulnerability with a CVSS score of 5.4 (MEDIUM). IDenticard Two-Reader Controller Configuration Manager 1.18.8 (396) is vulnerable to Stored Cross-Site Scripting (XSS) via the notes field in /~user_handler?file=logged_in.shtm (aka the edit user page...
How severe is CVE-2017-14973?
CVE-2017-14973 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14973?
Check the references section above for vendor advisories and patch information. Affected products include: Identicard Two-Reader Controller Configuration Manager.