355
VMScore

CVE-2017-13754

Published: 07/09/2017 Updated: 09/10/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the "advanced settings - time server" module in Wibu-Systems CodeMeter prior to 6.50b allows remote malicious users to inject arbitrary web script or HTML via the "server name" field in actions/ChangeConfiguration.html.

Vulnerable Product Search on Vulmon Subscribe to Product

wibu codemeter

Exploits

Document Title: =============== Wibu Systems AG CodeMeter 650 - Persistent XSS Vulnerability References (Source): ==================== wwwvulnerability-labcom/get_contentphp?id=2074 ID: FB49498 Acknowledgements: wwwflickrcom/photos/vulnerabilitylab/36912680045/ webnvdnistgov/view/vuln/detail?vulnId=CVE-2017-1375 ...
Wibu Systems AG CodeMeter version 650 suffers from a persistent cross site scripting vulnerability ...