CVE-2017-10795: XSS
Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or HTML via the body to blog/add/, a different vulnerability than CVE-2017-6069.
Other sources
Cross-site scripting (XSS) vulnerability in Subrion CMS allows remote attackers to inject arbitrary web script or HTML via the body to blog/add/, a different vulnerability than CVE-2017-6069.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10795?
CVE-2017-10795 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How can I mitigate CVE-2017-10795?
To mitigate CVE-2017-10795, it is recommended to upgrade Subrion CMS to version 4.1.6 or later.
What impact does CVE-2017-10795 have on my website?
CVE-2017-10795 allows attackers to inject arbitrary web scripts or HTML, potentially compromising user data and site integrity.
Which versions of Subrion CMS are affected by CVE-2017-10795?
CVE-2017-10795 affects Subrion CMS version 4.1.4 and earlier.
Is there a specific attack vector for CVE-2017-10795?
The specific attack vector for CVE-2017-10795 is through the body parameter when adding new blog entries.