CVE-2017-14756: XSS
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Cross-Site Scripting: /xAdmin/html/Deployment (catid).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14756?
CVE-2017-14756 is classified as a medium severity vulnerability due to its potential for exploiting Cross-Site Scripting vulnerabilities.
How do I fix CVE-2017-14756?
To mitigate CVE-2017-14756, ensure that you apply the latest updates or patches provided by OpenText for Document Sciences xPression.
What types of attacks can CVE-2017-14756 exploit?
CVE-2017-14756 can be exploited to perform Cross-Site Scripting attacks, allowing an attacker to inject malicious scripts into web pages.
Which versions of OpenText Document Sciences xPression are affected by CVE-2017-14756?
CVE-2017-14756 affects OpenText Document Sciences xPression v4.5SP1 Patch 13 and possibly older versions.
How does CVE-2017-14756 impact users of OpenText Document Sciences xPression?
Users of OpenText Document Sciences xPression may face security risks, including data theft or session hijacking, due to Cross-Site Scripting vulnerabilities in CVE-2017-14756.