5.4
CVSSv3

CVE-2017-14717

Published: 22/09/2017 Updated: 06/10/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

telaxius epesi

Exploits

# Exploit Title: Multiple Stored XSS in EPESI # Date: 10/03/2017 # Exploit Author: Zeeshan Shaikh # Vendor Homepage: epesi/ # Software Link: epesi/download/ # Version: 182 rev20170830 # CVE : CVE-2017-14712 to CVE-2017-14717 # Category: webapps XSS 1 (Tasks - Title) Steps to recreate: 1 Home->Tasks->add new 2 Enter title ...
EPESI version 182 revision 20170830 suffers from a cross site scripting vulnerability ...