3.5
CVSSv2

CVE-2017-9516

Published: 08/06/2017 Updated: 13/08/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Craft CMS prior to 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

craftcms craft cms

Exploits

# Exploit Title: Craft CMS 26 - Cross-Site Scripting/Unrestricted File Upload # Date: 2017-06-08 # Exploit Author: Ahsan Tahir # Vendor Homepage: craftcmscom # Software Link: downloadcraftcdncom/craft/26/262981/Craft-262981zip # Version: 26 # Tested on: [Kali Linux 20 | Windows 81] # Email: mrahsan1337@gmailcom # Contac ...