Stored Cross-Site Scripting Vulnerability in Sulu-standard by Sulu
CVE-2017-1000465

5.4MEDIUM

Key Information:

Vendor

Sulu

Vendor
CVE Published:
9 January 2018

What is CVE-2017-1000465?

Sulu-standard version 1.6.6 contains a stored cross-site scripting vulnerability within the page creation interface. This flaw enables attackers to inject malicious JavaScript code, which can lead to service disruption and unauthorized actions on behalf of users. Proper input validation and output encoding practices are recommended to mitigate such risks.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.