CVE-2017-8052: XSS
Published Apr 22, 2017
·Updated
Craft CMS before 2.6.2974 allows XSS attacks.
Affected Software
2 affected componentsFixes available
composer/craftcms/cms<2.6.2974
2.6.2974
Craft CMS<=2.6.2973
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/craftcms/cmsto a version that resolves this vulnerability.Fixed in 2.6.2974
Event History
Apr 22, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:59 AM
DescriptionSeverityWeaknessAffected Software
May 17, 2022
Advisory Published
02:48 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-8052?
CVE-2017-8052 is classified as a medium severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2017-8052?
To fix CVE-2017-8052, you should upgrade to Craft CMS version 2.6.2974 or later.
3
What type of vulnerability is CVE-2017-8052?
CVE-2017-8052 is an XSS (Cross-Site Scripting) vulnerability.
4
What versions of Craft CMS are affected by CVE-2017-8052?
Versions of Craft CMS up to and including 2.6.2973 are affected by CVE-2017-8052.
5
Is there a patch for CVE-2017-8052?
Yes, a patch is included in Craft CMS version 2.6.2974 which resolves CVE-2017-8052.