First published: Wed Mar 15 2017(Updated: )
Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian GNU/Linux | =8.0 | |
openSUSE | =42.2 | |
openSUSE Leap | =42.1 | |
ViewVC | <=1.1.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-5938 is classified as medium due to its potential impact on web application security.
To fix CVE-2017-5938, update ViewVC to version 1.0.14 or 1.1.26 or later.
CVE-2017-5938 affects ViewVC versions up to 1.1.25 and specific versions of Debian and openSUSE.
CVE-2017-5938 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2017-5938 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.