Stored Cross-Site Scripting Vulnerability in PluXml by PluXml
CVE-2017-1001001

5.4MEDIUM

Key Information:

Vendor

Pluxml

Status
Vendor
CVE Published:
1 November 2017

What is CVE-2017-1001001?

The PluXml version 5.6 is vulnerable to a stored cross-site scripting issue on the article creation page. This flaw allows an attacker to inject malicious scripts, leading to unauthorized privilege escalation and potentially compromising the integrity of the application and its users. Proper validation and sanitization of user inputs are crucial to mitigate this vulnerability.

Affected Version(s)

PluXml before 5.6

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.
CVE-2017-1001001 : Stored Cross-Site Scripting Vulnerability in PluXml by PluXml