5.4
CVSSv3

CVE-2017-16807

Published: 13/11/2017 Updated: 02/08/2019
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A cross-site Scripting (XSS) vulnerability in Kirby Panel prior to 2.3.3, 2.4.x prior to 2.4.2, and 2.5.x prior to 2.5.7 exists when displaying a specially prepared SVG document that has been uploaded as a content file.

Vulnerable Product Search on Vulmon Subscribe to Product

getkirby panel

Exploits

# Exploit Title: KirbyCMS <257 Stored Cross Site Scripting # Vendor Homepage: getkirbycom/ # Software Link: getkirbycom/try # Discovered by: Ishaq Mohammed # Contact: twittercom/security_prince # Website: aboutme/security-prince # Category: webapps # Platform: PHP # CVE: CVE-2017-16807 1 Description A ...