6.1
CVSSv3

CVE-2017-0378

Published: 20/07/2017 Updated: 26/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

XSS exists in the login_form function in views/helpers.php in Phamm prior to 0.6.7, exploitable via the PATH_INFO to main.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phamm phamm

Vendor Advisories

Debian Bug report logs - #868988 phamm: CVE-2017-0378 reflected XSS in phamm Package: src:phamm; Maintainer for src:phamm is Phamm Team <team@phammorg>; Reported by: John Lightsey <lightsey@debianorg> Date: Thu, 20 Jul 2017 00:57:02 UTC Severity: grave Tags: fixed-upstream, security, upstream Found in version pham ...