CVE-2017-11287: XSS
Published Dec 9, 2017
·Updated
An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A reflected cross-site scripting vulnerability exists that can result in information disclosure.
Affected Software
1 affected component
Adobe Connect<=9.6.2
Event History
Dec 9, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-11287?
The severity of CVE-2017-11287 is medium, with a severity value of 6.1.
2
What is the vulnerability in Adobe Connect 9.6.2 and earlier versions?
The vulnerability in Adobe Connect 9.6.2 and earlier versions is a reflected cross-site scripting (XSS) vulnerability.
3
How can the vulnerability in Adobe Connect 9.6.2 and earlier version be exploited?
The vulnerability in Adobe Connect 9.6.2 and earlier versions can be exploited by tricking a user into clicking on a specially crafted link that executes malicious scripts.
4
What can the exploitation of CVE-2017-11287 result in?
The exploitation of CVE-2017-11287 can result in information disclosure.
5
Is there a fix available for CVE-2017-11287?
Yes, Adobe has released a security bulletin (APSB17-35) that includes patches to address the vulnerability.