CVE-2017-5494: XSS
Published Jan 15, 2017
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in the file types table in b2evolution through 6.8.3 allow remote authenticated users to inject arbitrary web script or HTML via a .swf file in a (1) comment frame or (2) avatar frame.
Affected Software
1 affected component
b2evolution b2evolution<=6.8.3
Remediation
Patch Available
Event History
Jan 15, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5494?
CVE-2017-5494 has been classified as a moderate severity vulnerability due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2017-5494?
To fix CVE-2017-5494, upgrade b2evolution to version 6.8.4 or later to eliminate the vulnerabilities.
3
Who is affected by CVE-2017-5494?
CVE-2017-5494 affects all users of b2evolution versions 6.8.3 and earlier.
4
What types of attacks can be performed using CVE-2017-5494?
CVE-2017-5494 can be exploited to perform cross-site scripting attacks through comments or avatar frames.
5
Is CVE-2017-5494 exploitable without authentication?
No, CVE-2017-5494 requires an authenticated user to exploit the vulnerabilities.