CVE-2017-5631

MEDIUM NUCLEI

CaseAware - Reflected Cross-Site Scripting via Login Page User Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-5631. PoCs published by justpentest. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in CaseAware's login.php via the 'usr' parameter. The PoC shows how an attacker can inject malicious JavaScript into the query string, which executes when the victim clicks the crafted link.

Description

An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the login.php query string.

Exploits (1)

exploitdb WORKING POC
by justpentest · textwebappsphp
https://www.exploit-db.com/exploits/42042

This exploit demonstrates a reflected XSS vulnerability in CaseAware's login.php via the 'usr' parameter. The PoC shows how an attacker can inject malicious JavaScript into the query string, which executes when the victim clicks the crafted link.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: CaseAware (all versions)
No auth needed
Prerequisites: Victim must click a crafted URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

KMCIS CaseAware - Cross-Site Scripting
MEDIUMby edoardottt
FOFA: title="caseaware"

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.openbugbounty.org/incidents/228262/
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/42042/

Scores

CVSS v3 6.1
EPSS 0.0449
EPSS Percentile 90.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
kmc_information_systems/caseaware
Published May 01, 2017
Tracked Since Feb 18, 2026