First published: Thu Sep 07 2017(Updated: )
Cross-site scripting (XSS) vulnerability in the "advanced settings - time server" module in Wibu-Systems CodeMeter before 6.50b allows remote attackers to inject arbitrary web script or HTML via the "server name" field in actions/ChangeConfiguration.html.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wibu CodeMeter | <=6.50a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-13754 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2017-13754, upgrade Wibu-Systems CodeMeter to version 6.50b or later.
CVE-2017-13754 allows remote attackers to inject arbitrary web scripts or HTML, potentially compromising user data.
CVE-2017-13754 affects Wibu-Systems CodeMeter versions prior to 6.50b, specifically up to version 6.50a.
You can identify exploitation attempts by monitoring logs for unusual inputs in the 'server name' field in the advanced settings.