CVE-2017-12138: Medium severity Xoops Xoops vulnerability
Published Aug 2, 2017
·Updated
XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter.
Affected Software
1 affected component
Xoops Xoops=2.5.8
Event History
Aug 2, 2017
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12138?
CVE-2017-12138 is rated as a medium severity vulnerability due to the potential for exploitation through URL redirection.
2
How do I fix CVE-2017-12138?
To fix CVE-2017-12138, upgrade to the latest version of XOOPS that addresses this vulnerability.
3
What impact does CVE-2017-12138 have on users?
CVE-2017-12138 allows attackers to bypass URL filters, which can lead to untrusted redirects affecting user security.
4
Is CVE-2017-12138 exploitable by all users?
CVE-2017-12138 can be exploited by unauthenticated attackers, making it critical to address quickly.
5
What versions of XOOPS are affected by CVE-2017-12138?
CVE-2017-12138 specifically affects XOOPS Core version 2.5.8.