Stored Cross-Site Scripting Vulnerability in BookStack by BookStackApp
CVE-2017-1000462

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 January 2018

What is CVE-2017-1000462?

The vulnerability in BookStack version 0.18.4 allows attackers to execute arbitrary JavaScript code through stored cross-site scripting on the page creation interface. This can lead to various malicious activities, including disruption of service and unauthorized access to sensitive information. The issue can arise when user inputs are not properly sanitized, allowing harmful scripts to be stored and executed when other users visit the affected pages.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.