CVE-2017-15686: XSS
Published Nov 27, 2020
·Updated
Crafter CMS Crafter Studio 3.0.1 is affected by: Cross Site Scripting (XSS), which allows remote attackers to steal users’ cookies.
Affected Software
1 affected component
CrafterCMS Crafter Cms>=3.0.0<3.0.1
Event History
Nov 27, 2020
CVE Published
via MITRE·05:24 PM
Data Sourced
via MITRE·05:24 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for Crafter CMS Crafter Studio 3.0.1?
The vulnerability ID for this version of Crafter CMS Crafter Studio is CVE-2017-15686.
2
What is the severity of CVE-2017-15686?
The severity of CVE-2017-15686 is medium with a CVSS score of 6.1.
3
What software version is affected by CVE-2017-15686?
Crafter CMS Crafter Studio version 3.0.1 is affected by CVE-2017-15686.
4
What is the impact of CVE-2017-15686?
CVE-2017-15686 allows remote attackers to steal users' cookies through Cross-Site Scripting (XSS) attacks.
5
Is there a fix available for CVE-2017-15686?
Yes, a fix is available for CVE-2017-15686. Please refer to the official advisory for more information: https://docs.craftercms.org/en/3.0/security/advisory.html