CVE-2017-11666: XSS
Published Jul 26, 2017
·Updated
Cross-site scripting (XSS) vulnerability in js/ViewerPanel.js in the file previewer plugin in Kopano WebApp versions 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a specially crafted previewable file.
Affected Software
1 affected component
Kopano WebApp<=3.3.0
Event History
Jul 26, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11666?
CVE-2017-11666 is considered a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2017-11666?
To fix CVE-2017-11666, upgrade Kopano WebApp to version 3.3.1 or later.
3
What versions are affected by CVE-2017-11666?
CVE-2017-11666 affects Kopano WebApp versions 3.3.0 and earlier.
4
What type of vulnerability is CVE-2017-11666?
CVE-2017-11666 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts.
5
Can CVE-2017-11666 be exploited remotely?
Yes, CVE-2017-11666 can be exploited remotely by attackers through specially crafted previewable files.