CVE-2017-6908: XSS
An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (fID) passed to the "concrete5-legacy-master/web/concrete/tools/files/selectordata.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6908?
CVE-2017-6908 has a moderate severity level, allowing potential cross-site scripting attacks.
How do I fix CVE-2017-6908?
To fix CVE-2017-6908, you should upgrade your Concrete5 installation to version 5.6.4 or later.
Who is impacted by CVE-2017-6908?
CVE-2017-6908 affects all versions of Concrete5 up to and including 5.6.3.4, allowing attackers to exploit unfiltered user-supplied data.
What type of attack is associated with CVE-2017-6908?
CVE-2017-6908 is associated with cross-site scripting (XSS) attacks due to insufficient data filtration.
What component is vulnerable in CVE-2017-6908?
The vulnerable component in CVE-2017-6908 is the selector_data.php tool in the Concrete5 legacy system.