CVE-2017-9783: XSS
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the Description field in a Site name updated.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-9783?
CVE-2017-9783 is a cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca.
What is the severity of CVE-2017-9783?
CVE-2017-9783 has a severity rating of 6.1 (Medium).
How does CVE-2017-9783 affect ProjectSend?
CVE-2017-9783 affects ProjectSend (formerly cFTP) versions up to and including r754.
How can remote attackers exploit CVE-2017-9783?
Remote attackers can exploit CVE-2017-9783 by injecting arbitrary web script or HTML via the Description field in a Site name updated.
Is there a fix available for CVE-2017-9783?
Yes, a fix for CVE-2017-9783 can be found in commit 6c3710430be26feb5371cb0377e5355d6f9a27ca of the ProjectSend repository.