First published: Mon Oct 02 2017(Updated: )
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Cross-Site Scripting: /xAdmin/html/XPressoDoc, parameter: categoryId.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Document Sciences xPression | <=4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14755 is considered a high severity vulnerability due to its potential for Cross-Site Scripting attacks.
To fix CVE-2017-14755, update OpenText Document Sciences xPression to version 4.5SP1 Patch 13 or later.
CVE-2017-14755 affects OpenText Document Sciences xPression v4.5SP1 Patch 13 and potentially older versions.
CVE-2017-14755 is a Cross-Site Scripting (XSS) vulnerability affecting certain parameters in the application.
Yes, exploitation of CVE-2017-14755 can lead to data breaches by allowing attackers to execute malicious scripts in the user's browser.