CVE-2017-1000023: XSS
Published Jul 13, 2017
·Updated
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document.
Affected Software
1 affected component
LogicalDOC LogicalDOC<=7.5.3
Event History
Jul 13, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000023?
CVE-2017-1000023 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2017-1000023?
To mitigate CVE-2017-1000023, upgrade LogicalDoc Community Edition to version 7.5.4 or later.
3
What type of vulnerability is CVE-2017-1000023?
CVE-2017-1000023 is an XSS (cross-site scripting) vulnerability.
4
Which versions of LogicalDoc are affected by CVE-2017-1000023?
CVE-2017-1000023 affects LogicalDoc Community Edition versions 7.5.3 and prior.
5
Can CVE-2017-1000023 be exploited remotely?
Yes, CVE-2017-1000023 can be exploited remotely if an attacker can craft a malicious HTML document.