CVE-2017-9338: XSS
Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2. To be exploitable a user has to write or paste malicious content into the search dialogue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9338?
CVE-2017-9338 is considered a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2017-9338?
To fix CVE-2017-9338, upgrade your ownCloud Server to version 8.2.12 or later, or to 9.0.10, 9.1.6, or 10.0.2 or later.
What systems are affected by CVE-2017-9338?
CVE-2017-9338 affects ownCloud Server versions prior to 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2.
Who can exploit CVE-2017-9338?
CVE-2017-9338 can be exploited by any user who can write or paste malicious content into the search dialogue.
What type of vulnerability is CVE-2017-9338?
CVE-2017-9338 is a cross-site scripting (XSS) vulnerability due to inadequate escaping in the search module.