CVE-2017-16807: XSS
A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exists when displaying a specially prepared SVG document that has been uploaded as a content file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16807?
CVE-2017-16807 is classified as a medium-severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2017-16807?
To fix CVE-2017-16807, upgrade to Kirby Panel version 2.5.7 or later, or the appropriate patched version based on your current version.
Which versions are affected by CVE-2017-16807?
CVE-2017-16807 affects Kirby Panel versions before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7.
What type of vulnerability is CVE-2017-16807?
CVE-2017-16807 is a cross-site scripting (XSS) vulnerability that allows attackers to execute scripts in the context of the user's browser.
What is the cause of CVE-2017-16807?
CVE-2017-16807 occurs when specially prepared SVG documents are uploaded as content files, leading to potential XSS attacks.