CVE-2017-13754: XSS
Cross-site scripting (XSS) vulnerability in the "advanced settings - time server" module in Wibu-Systems CodeMeter before 6.50b allows remote attackers to inject arbitrary web script or HTML via the "server name" field in actions/ChangeConfiguration.html.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13754?
CVE-2017-13754 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2017-13754?
To fix CVE-2017-13754, upgrade Wibu-Systems CodeMeter to version 6.50b or later.
What impact does CVE-2017-13754 have on my system?
CVE-2017-13754 allows remote attackers to inject arbitrary web scripts or HTML, potentially compromising user data.
Which versions of Wibu-Systems CodeMeter are affected by CVE-2017-13754?
CVE-2017-13754 affects Wibu-Systems CodeMeter versions prior to 6.50b, specifically up to version 6.50a.
How can I identify CVE-2017-13754 exploitation attempts?
You can identify exploitation attempts by monitoring logs for unusual inputs in the 'server name' field in the advanced settings.