Vulnerability Description
Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.
CVSS Score
6.1
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rendertron | 1.0.0 |
Related Weaknesses (CWE)
References
- https://bugs.chromium.org/p/chromium/issues/detail?id=759111ExploitIssue TrackingThird Party Advisory
- https://github.com/GoogleChrome/rendertron/commit/8d70628c96ae72eff6eebb451d26fcPatch
- https://github.com/GoogleChrome/rendertron/pull/88PatchThird Party Advisory
- https://bugs.chromium.org/p/chromium/issues/detail?id=759111ExploitIssue TrackingThird Party Advisory
- https://github.com/GoogleChrome/rendertron/commit/8d70628c96ae72eff6eebb451d26fcPatch
- https://github.com/GoogleChrome/rendertron/pull/88PatchThird Party Advisory
FAQ
What is CVE-2017-18352?
CVE-2017-18352 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.
How severe is CVE-2017-18352?
CVE-2017-18352 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-18352?
Check the references section above for vendor advisories and patch information. Affected products include: Google Rendertron.