CVE-2017-11727: XSS
services/systemio/actionprocessor/Contact.rails in ConnectWise Manage 2017.5 allows arbitrary client-side JavaScript code execution (involving a ContactCommon field) on victims who click on a crafted link, aka XSS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11727?
CVE-2017-11727 is classified as a medium severity vulnerability due to its potential for arbitrary client-side JavaScript execution.
How do I fix CVE-2017-11727?
To fix CVE-2017-11727, update ConnectWise Manage to the latest version where the vulnerability has been patched.
What impact does CVE-2017-11727 have on users?
CVE-2017-11727 allows attackers to execute arbitrary JavaScript in the context of a victim's browser, which can lead to unauthorized actions or data theft.
Who is affected by CVE-2017-11727?
CVE-2017-11727 affects users of ConnectWise Manage version 2017.5.
Is user input related to CVE-2017-11727 vulnerable?
Yes, user input in the ContactCommon field can be exploited for cross-site scripting (XSS) attacks as per CVE-2017-11727.