Cross-Site Scripting Vulnerability in Adobe RoboHelp
CVE-2017-3104

6.1MEDIUM

Key Information:

Vendor
Adobe
Vendor
CVE Published:
1 December 2017

Summary

Adobe RoboHelp is susceptible to a cross-site scripting (XSS) vulnerability that can allow an attacker to execute arbitrary script code in the context of the user's session. This flaw is present in versions of RoboHelp prior to RH12.0.4.460 and RH2017 before RH2017.0.2. Successful exploitation could lead to unauthorized access to sensitive information and impact the security of the affected web applications.

Affected Version(s)

Adobe RoboHelp RH2017.0.1 and earlier Adobe RoboHelp RH2017.0.1 and earlier versions

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.