Loading HuntDB...

CVE-2017-18024

UNKNOWN
Published 2018-01-10T18:00:00
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2017-18024. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

AvantFAX 3.3.3 has XSS via an arbitrary parameter name to the default URI, as demonstrated by a parameter whose name contains a SCRIPT element and whose value is 1.

Available Exploits

AvantFAX 3.3.3 - Cross-Site Scripting

AvantFAX 3.3.3 contains a cross-site scripting vulnerability via an arbitrary parameter name submitted to the default URL, as demonstrated by a parameter whose name contains a SCRIPT element and whose value is 1.

ID: CVE-2017-18024
Author: pikpikcu Medium

Related News

No news articles found for this CVE.

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

⚠ Unreviewed MODERATE

GHSA-pgvh-2fg3-frgm

Advisory Details

AvantFAX 3.3.3 has XSS via an arbitrary parameter name to the default URI, as demonstrated by a parameter whose name contains a SCRIPT element and whose value is 1.

CVSS Scoring

CVSS Score

5.0

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Advisory provided by GitHub Security Advisory Database. Published: May 14, 2022, Modified: May 14, 2022

References

HackerOne Reports

pirneci
Endless Group
Cross-site Scripting (XSS) - Generic
Published: 2018-01-10T18:00:00
Last Modified: 2024-08-05T21:06:50.120Z
Copied to clipboard!