CVE-2017-8384: XSS
Published May 1, 2017
·Updated
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
Affected Software
2 affected componentsFixes available
composer/craftcms/cms<2.6.2976
2.6.2976
Craft CMS<=2.6.2974
Event History
May 1, 2017
CVE Published
via MITRE·06:08 AM
Data Sourced
via MITRE·06:08 AM
Description
May 17, 2022
Advisory Published
02:46 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-8384?
CVE-2017-8384 is classified as a medium severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2017-8384?
To fix CVE-2017-8384, upgrade to Craft CMS version 2.6.2976 or later.
3
What types of attacks can CVE-2017-8384 enable?
CVE-2017-8384 can enable cross-site scripting (XSS) attacks.
4
What versions of Craft CMS are affected by CVE-2017-8384?
Craft CMS versions prior to 2.6.2976, including 2.6.2974 and earlier, are affected by CVE-2017-8384.
5
Is CVE-2017-8384 a result of a previous vulnerability?
Yes, CVE-2017-8384 is related to an incomplete fix for CVE-2017-8052.