Lucene search

K
cvelistHackeroneCVELIST:CVE-2017-0912
HistoryJul 03, 2018 - 9:00 p.m.

CVE-2017-0912

2018-07-0321:00:00
hackerone
www.cve.org
4

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

21.7%

Ubiquiti UCRM versions 2.5.0 to 2.7.7 are vulnerable to Stored Cross-site Scripting. Due to the lack sanitization, it is possible to inject arbitrary HTML code by manipulating the uploaded filename. Successful exploitation requires valid credentials to an account with β€œEdit” access to β€œScheduling”.

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

21.7%

Related for CVELIST:CVE-2017-0912