CVE-2017-14036: XSS
Published Aug 30, 2017
·Updated
CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.
Affected Software
5 affected components
CrushFTP Crushftp<=7.7.0
CrushFTP Crushftp=8.0.2
CrushFTP Crushftp=8.0.3
CrushFTP Crushftp=8.0.4
CrushFTP Crushftp=8.1.0
Event History
Aug 30, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14036?
CVE-2017-14036 has a medium severity rating due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-14036?
To fix CVE-2017-14036, you should upgrade to CrushFTP version 7.8.0 or 8.2.0 or later.
3
What versions of CrushFTP are affected by CVE-2017-14036?
CVE-2017-14036 affects CrushFTP versions earlier than 7.8.0 and any 8.x versions prior to 8.2.0.
4
Can CVE-2017-14036 be exploited remotely?
Yes, CVE-2017-14036 can be exploited remotely through malicious scripts aimed at vulnerable web interfaces.
5
What are the potential impacts of CVE-2017-14036?
The potential impacts of CVE-2017-14036 include unauthorized access to user sessions and manipulation of web content.