Vulnerability Details CVE-2017-6908
An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (fID) passed to the "concrete5-legacy-master/web/concrete/tools/files/selector_data.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.1%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2017-6908
-
cpe:2.3:a:concrete5:concrete5:5.4.2
-
cpe:2.3:a:concrete5:concrete5:5.4.2.1
-
cpe:2.3:a:concrete5:concrete5:5.4.2.2
-
cpe:2.3:a:concrete5:concrete5:5.5.0
-
cpe:2.3:a:concrete5:concrete5:5.5.1
-
cpe:2.3:a:concrete5:concrete5:5.5.2
-
cpe:2.3:a:concrete5:concrete5:5.5.2.1
-
cpe:2.3:a:concrete5:concrete5:5.6.0
-
cpe:2.3:a:concrete5:concrete5:5.6.0.1
-
cpe:2.3:a:concrete5:concrete5:5.6.0.2
-
cpe:2.3:a:concrete5:concrete5:5.6.1
-
cpe:2.3:a:concrete5:concrete5:5.6.1.1
-
cpe:2.3:a:concrete5:concrete5:5.6.1.2
-
cpe:2.3:a:concrete5:concrete5:5.6.2
-
cpe:2.3:a:concrete5:concrete5:5.6.2.1
-
cpe:2.3:a:concrete5:concrete5:5.6.3
-
cpe:2.3:a:concrete5:concrete5:5.6.3.1
-
cpe:2.3:a:concrete5:concrete5:5.6.3.3