Vulnerability Description
Multiple persistent stored Cross-Site-Scripting (XSS) vulnerabilities in the files /wb/admin/admintools/tool.php (Droplet Description) and /install/index.php (Site Title) in WebsiteBaker 2.10.0 allow attackers to insert persistent JavaScript code that gets reflected back to users in multiple areas in the application.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Websitebaker | Websitebaker | 2.10.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/anonymous/13df19c04c7e86c0f5256b91376d593aThird Party Advisory
- https://gist.github.com/anonymous/13df19c04c7e86c0f5256b91376d593aThird Party Advisory
FAQ
What is CVE-2017-16514?
CVE-2017-16514 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Multiple persistent stored Cross-Site-Scripting (XSS) vulnerabilities in the files /wb/admin/admintools/tool.php (Droplet Description) and /install/index.php (Site Title) in WebsiteBaker 2.10.0 allow ...
How severe is CVE-2017-16514?
CVE-2017-16514 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-16514?
Check the references section above for vendor advisories and patch information. Affected products include: Websitebaker Websitebaker.