First published: Wed Jul 26 2017(Updated: )
Cross-site scripting (XSS) vulnerability in js/ViewerPanel.js in the file previewer plugin in Kopano WebApp versions 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a specially crafted previewable file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kopano WebApp | <=3.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11666 is considered a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2017-11666, upgrade Kopano WebApp to version 3.3.1 or later.
CVE-2017-11666 affects Kopano WebApp versions 3.3.0 and earlier.
CVE-2017-11666 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts.
Yes, CVE-2017-11666 can be exploited remotely by attackers through specially crafted previewable files.