CVE-2017-16821: XSS
Published Nov 15, 2017
·Updated
b3log Symphony (aka Sym) 2.2.0 has XSS in processor/AdminProcessor.java in the admin console, as demonstrated by a crafted X-Forwarded-For HTTP header that is mishandled during display of a client IP address in /admin/user/userid.
Affected Software
1 affected component
b3log Symphony=2.2.0
Event History
Nov 15, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16821?
The severity of CVE-2017-16821 is classified as medium due to its potential for Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2017-16821?
To fix CVE-2017-16821, update to a patched version of b3log Symphony that addresses the XSS vulnerability in the admin console.
3
What software versions are affected by CVE-2017-16821?
CVE-2017-16821 specifically affects b3log Symphony version 2.2.0.
4
What kind of vulnerability is CVE-2017-16821?
CVE-2017-16821 is a Cross-Site Scripting (XSS) vulnerability that occurs in the admin console.
5
What areas of the application does CVE-2017-16821 impact?
CVE-2017-16821 impacts the display of client IP addresses in the admin/user/userid section of the application.