CVE-2017-7352: XSS
Stored Cross-site scripting (XSS) vulnerability in Pure Storage Purity 4.7.5 allows remote authenticated users to inject arbitrary web script or HTML via the "host" parameter on the 'System > Configuration > SNMP > Add SNMP Trap Manager' screen.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7352?
CVE-2017-7352 is classified as a medium severity vulnerability due to its potential impact when exploited.
How do I fix CVE-2017-7352?
To fix CVE-2017-7352, upgrade to Pure Storage Purity version 4.8 or later, which addresses this vulnerability.
What type of vulnerability is CVE-2017-7352?
CVE-2017-7352 is a stored cross-site scripting (XSS) vulnerability affecting Pure Storage Purity 4.7.5.
Who is affected by CVE-2017-7352?
Remote authenticated users of Pure Storage Purity 4.7.5 can be affected by the CVE-2017-7352 vulnerability.
What can an attacker do with CVE-2017-7352?
An attacker can inject arbitrary web script or HTML into the application via the 'host' parameter, potentially causing harm to users.