CVE-2017-0912: XSS
Ubiquiti UCRM versions 2.5.0 to 2.7.7 are vulnerable to Stored Cross-site Scripting. Due to the lack sanitization, it is possible to inject arbitrary HTML code by manipulating the uploaded filename. Successful exploitation requires valid credentials to an account with "Edit" access to "Scheduling".
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0912?
CVE-2017-0912 is considered a medium severity vulnerability due to its potential for Stored Cross-site Scripting attacks.
How do I fix CVE-2017-0912?
To mitigate CVE-2017-0912, upgrade Ubiquiti UCRM to version 2.8.2 or later, which addresses the vulnerability.
What software versions are affected by CVE-2017-0912?
CVE-2017-0912 affects Ubiquiti UCRM versions 2.5.0 to 2.7.7.
Can CVE-2017-0912 be exploited without valid credentials?
No, successful exploitation of CVE-2017-0912 requires valid credentials to an account with 'Edit' access to 'Scheduling'.
What type of attack does CVE-2017-0912 involve?
CVE-2017-0912 involves a Stored Cross-site Scripting attack, allowing the injection of arbitrary HTML code.