Vulnerability Description
GeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter. NOTE: this might overlap CVE-2017-14761, CVE-2017-14762, or CVE-2017-14765.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Genixcms | Genixcms | 1.1.5 |
Related Weaknesses (CWE)
References
- https://code610.blogspot.com/2017/12/modus-operandi-genixcms-115.htmlExploitThird Party Advisory
- https://code610.blogspot.com/2017/12/modus-operandi-genixcms-115.htmlExploitThird Party Advisory
FAQ
What is CVE-2017-17431?
CVE-2017-17431 is a vulnerability with a CVSS score of 6.1 (MEDIUM). GeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter. NOTE: this might overlap CVE-2017-14761, CVE-2017-14762, or CVE-2017-14765.
How severe is CVE-2017-17431?
CVE-2017-17431 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17431?
Check the references section above for vendor advisories and patch information. Affected products include: Genixcms Genixcms.