CVE-2017-18217: XSS
An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and application/modules/quotes/views/view.php.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18217?
CVE-2017-18217 has a medium severity level due to its Cross Site Scripting vulnerability that may lead to unauthorized actions.
How do I fix CVE-2017-18217?
To fix CVE-2017-18217, upgrade InvoicePlane to version 1.5.5 or later, where the vulnerability has been addressed.
What components of InvoicePlane are affected by CVE-2017-18217?
CVE-2017-18217 affects the Email address and Web address parameters in clients, invoices, and quotes views.
What type of vulnerability is CVE-2017-18217?
CVE-2017-18217 is a Cross Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
Is CVE-2017-18217 prevalent in all versions of InvoicePlane?
CVE-2017-18217 is prevalent in all versions of InvoicePlane prior to 1.5.5.