Record summary

CVE-2017-5963 has a selected CVSS score of 6.1 (medium).

Description

An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy/Resources/Public/JavaScript/e-payment/paymill/api/php/payment.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 26, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

References

3