Cross Site Scripting Flaw in Croogo by Croogo
CVE-2017-1000510

5.4MEDIUM

Key Information:

Vendor

Croogo

Status
Vendor
CVE Published:
9 February 2018

What is CVE-2017-1000510?

Croogo version 2.3.1-17-g6f82e6c is affected by a Cross Site Scripting (XSS) vulnerability found in the Page name functionality. This flaw allows malicious actors to inject and execute JavaScript code, potentially compromising the security of the application and its users. Effective security measures must be implemented to safeguard against such exploits and to ensure web application integrity.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-1000510 : Cross Site Scripting Flaw in Croogo by Croogo