CVE-2016-5663: XSS
Multiple cross-site scripting (XSS) vulnerabilities in oauthcallback.php on Accellion Kiteworks appliances before kw2016.03.00 allow remote attackers to inject arbitrary web script or HTML via the (1) code, (2) error, or (3) errordescription parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5663?
CVE-2016-5663 is classified as a medium severity vulnerability due to its potential impact through cross-site scripting attacks.
How do I fix CVE-2016-5663?
To fix CVE-2016-5663, upgrade your Accellion Kiteworks appliance to version kw2016.03.00 or later.
What are the affected parameters in CVE-2016-5663?
The affected parameters in CVE-2016-5663 include code, error, and error_description.
Can CVE-2016-5663 be exploited remotely?
Yes, CVE-2016-5663 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.
What software versions are impacted by CVE-2016-5663?
All versions of Accellion Kiteworks appliances before kw2016.03.00 are impacted by CVE-2016-5663.