CVE-2017-9306: XSS
Published May 31, 2017
·Updated
inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" substring instead of an "<svg onload=" substring.
Affected Software
1 affected component
sysPass SysPass=2.1.9
Event History
May 31, 2017
CVE Published
via MITRE·03:54 AM
Data Sourced
via MITRE·03:54 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9306?
CVE-2017-9306 is considered a medium severity vulnerability due to its potential to allow remote attackers to bypass XSS filters.
2
How do I fix CVE-2017-9306?
To fix CVE-2017-9306, update sysPass to version 2.1.10 or later which includes the necessary security patches.
3
What types of attacks can exploit CVE-2017-9306?
CVE-2017-9306 can be exploited to inject malicious scripts via the vulnerable XSS filter bypass, enabling cross-site scripting attacks.
4
Which version of sysPass is affected by CVE-2017-9306?
CVE-2017-9306 affects sysPass version 2.1.9.
5
Where can I report an incident related to CVE-2017-9306?
Incidents related to CVE-2017-9306 should be reported to the relevant security teams or directly to the sysPass maintainers.