Vulnerability Description
The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the self Smarty tag.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotx | Pivotx | 2.3.11 |
Related Weaknesses (CWE)
References
- https://sourceforge.net/p/pivot-weblog/code/4487/Third Party Advisory
- https://sourceforge.net/p/pivot-weblog/code/4487/Third Party Advisory
FAQ
What is CVE-2017-9332?
CVE-2017-9332 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the self Smarty tag.
How severe is CVE-2017-9332?
CVE-2017-9332 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9332?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotx Pivotx.