CVE-2017-1000466: XSS
Published Jan 3, 2018
·Updated
Invoice Ninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page, which can result in disruption of service and execution of javascript code.
Affected Software
1 affected component
invoiceninja Invoice Ninja=3.8.1
Event History
Jan 3, 2018
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000466?
CVE-2017-1000466 has a medium severity rating due to its potential for stored cross-site scripting attacks.
2
How do I fix CVE-2017-1000466?
To fix CVE-2017-1000466, update Invoice Ninja to version 3.8.2 or later where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2017-1000466?
CVE-2017-1000466 is classified as a stored cross-site scripting (XSS) vulnerability.
4
What are the potential impacts of CVE-2017-1000466?
The potential impacts of CVE-2017-1000466 include disruption of service and execution of malicious JavaScript code.
5
Which software version is affected by CVE-2017-1000466?
CVE-2017-1000466 affects Invoice Ninja version 3.8.1.