First published: Mon Jan 08 2018(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Gespage before 7.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) printer name when adding a printer in the admin panel or (2) username parameter to webapp/users/user_reg.jsp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WP Links Page | <7.4.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7998 is classified as a medium severity vulnerability due to its ability to allow attackers to execute arbitrary scripts.
To address CVE-2017-7998, upgrade Gespage to version 7.4.9 or later.
CVE-2017-7998 is associated with cross-site scripting (XSS) attacks via manipulations of the printer name and username parameters.
Any users of Gespage versions prior to 7.4.9 are potentially affected by CVE-2017-7998.
Exploiting CVE-2017-7998 can lead to unauthorized access, data leakage, and malicious content execution in the user's browser.