Vulnerability Description
Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Flatcore | Flatcore | 1.4.6 |
Related Weaknesses (CWE)
References
- https://github.com/flatCore/flatCore-CMS/commit/f1b42b338693a9c240182e76ef213105Patch
- https://github.com/flatCore/flatCore-CMS/issues/34Issue TrackingThird Party Advisory
- https://github.com/flatCore/flatCore-CMS/commit/f1b42b338693a9c240182e76ef213105Patch
- https://github.com/flatCore/flatCore-CMS/issues/34Issue TrackingThird Party Advisory
FAQ
What is CVE-2017-9451?
CVE-2017-9451 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized ...
How severe is CVE-2017-9451?
CVE-2017-9451 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9451?
Check the references section above for vendor advisories and patch information. Affected products include: Flatcore Flatcore.