Vulnerability Details CVE-2017-9783
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the Description field in a Site name updated.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.0%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2017-9783
-
cpe:2.3:a:projectsend:projectsend:100
-
cpe:2.3:a:projectsend:projectsend:102
-
cpe:2.3:a:projectsend:projectsend:105
-
cpe:2.3:a:projectsend:projectsend:1053
-
cpe:2.3:a:projectsend:projectsend:1070
-
cpe:2.3:a:projectsend:projectsend:110
-
cpe:2.3:a:projectsend:projectsend:155
-
cpe:2.3:a:projectsend:projectsend:156
-
cpe:2.3:a:projectsend:projectsend:157
-
cpe:2.3:a:projectsend:projectsend:161
-
cpe:2.3:a:projectsend:projectsend:180
-
cpe:2.3:a:projectsend:projectsend:335
-
cpe:2.3:a:projectsend:projectsend:375
-
cpe:2.3:a:projectsend:projectsend:405
-
cpe:2.3:a:projectsend:projectsend:412
-
cpe:2.3:a:projectsend:projectsend:514
-
cpe:2.3:a:projectsend:projectsend:559
-
cpe:2.3:a:projectsend:projectsend:561
-
cpe:2.3:a:projectsend:projectsend:582
-
cpe:2.3:a:projectsend:projectsend:753
-
cpe:2.3:a:projectsend:projectsend:754
-
cpe:2.3:a:projectsend:projectsend:756
-
cpe:2.3:a:projectsend:projectsend:r375
-
cpe:2.3:a:projectsend:projectsend:r405
-
cpe:2.3:a:projectsend:projectsend:r412
-
cpe:2.3:a:projectsend:projectsend:r514
-
cpe:2.3:a:projectsend:projectsend:r559
-
cpe:2.3:a:projectsend:projectsend:r561
-
cpe:2.3:a:projectsend:projectsend:r571
-
cpe:2.3:a:projectsend:projectsend:r572
-
cpe:2.3:a:projectsend:projectsend:r582
-
cpe:2.3:a:projectsend:projectsend:r609
-
cpe:2.3:a:projectsend:projectsend:r753
-
cpe:2.3:a:projectsend:projectsend:r754