5.4
CVSSv3

CVE-2017-1001001

Published: 01/11/2017 Updated: 07/11/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

pluxml pluxml 5.6

Vendor Advisories

Debian Bug report logs - #881796 CVE-2017-1001001: pluxml: XSS and missing httponly flag Package: pluxml; Maintainer for pluxml is Tanguy Ortolo <tanguy+debian@ortoloeu>; Source for pluxml is src:pluxml (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Wed, 15 Nov 2017 07:18:02 UTC Severity: grave ...