CVE-2017-5938: XSS
Published Mar 15, 2017
·Updated
Cross-site scripting (XSS) vulnerability in the navpath function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the navdata name.
Affected Software
4 affected components
Debian Debian Linux=8.0
openSUSE Leap=42.2
Opensuse Project Leap=42.1
viewvc ViewVC<=1.1.25
Remediation
Patch Available
Event History
Mar 15, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5938?
The severity of CVE-2017-5938 is classified as medium due to its potential impact on web application security.
2
How do I fix CVE-2017-5938?
To fix CVE-2017-5938, update ViewVC to version 1.0.14 or 1.1.26 or later.
3
Which software is affected by CVE-2017-5938?
CVE-2017-5938 affects ViewVC versions up to 1.1.25 and specific versions of Debian and openSUSE.
4
What type of vulnerability is CVE-2017-5938?
CVE-2017-5938 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2017-5938 be exploited remotely?
Yes, CVE-2017-5938 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.