CVE-2017-9516: XSS
Published Jun 8, 2017
·Updated
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
Affected Software
2 affected componentsFixes available
composer/craftcms/cms<2.6.2982
2.6.2982
Craft CMS<=2.6.2981
Event History
Jun 8, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
May 17, 2022
Advisory Published
02:14 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-9516?
CVE-2017-9516 has a medium severity level due to the potential for XSS attacks.
2
How do I fix CVE-2017-9516?
To fix CVE-2017-9516, upgrade to Craft CMS version 2.6.2982 or later.
3
What type of attack does CVE-2017-9516 expose?
CVE-2017-9516 exposes the application to a potential cross-site scripting (XSS) attack through malicious SVG file uploads.
4
Which versions of Craft CMS are affected by CVE-2017-9516?
Craft CMS versions prior to 2.6.2982 are affected by CVE-2017-9516.
5
Is there any mitigation for CVE-2017-9516 if upgrading is not possible?
If upgrading is not possible, consider disabling the upload of SVG files to mitigate CVE-2017-9516.