CVE-2017-8016: XSS
RSA Archer GRC Platform prior to 6.2.0.5 is affected by stored cross-site scripting via the Questionnaire ID field. An authenticated attacker may potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8016?
The severity of CVE-2017-8016 is considered medium due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2017-8016?
To fix CVE-2017-8016, upgrade the RSA Archer GRC Platform to version 6.2.0.5 or higher.
What vulnerable software versions are affected by CVE-2017-8016?
RSA Archer GRC Platform versions prior to 6.2.0.5 are vulnerable to CVE-2017-8016.
What type of attack can CVE-2017-8016 facilitate?
CVE-2017-8016 can facilitate stored cross-site scripting attacks allowing execution of arbitrary HTML in user sessions.
Who can exploit CVE-2017-8016?
An authenticated attacker can exploit CVE-2017-8016 to execute arbitrary scripts in the context of the affected application.