4.3
CVSSv2

CVE-2017-9072

Published: 18/05/2017 Updated: 18/01/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Two CalendarXP products have XSS in common parts of HTML files. CalendarXP FlatCalendarXP up to and including 9.9.290 has XSS in iflateng.htm and nflateng.htm. CalendarXP PopCalendarXP up to and including 9.8.308 has XSS in ipopeng.htm and npopeng.htm.

Vulnerable Product Search on Vulmon Subscribe to Product

calendarxp flatcalendarxp

calendarxp popcalendarxp

Exploits

RS Authentication Manager versions prior to 83 P1 suffer from cross site scripting and XML external entity injection vulnerabilities ...