96198vdb entry
http://www.securityfocus.com/bid/96198 CVE-2017-5963
MEDIUM
caddy_project caddy Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2017-5963 has a selected CVSS score of 6.1 (medium).
Description
An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy/Resources/Public/JavaScript/e-payment/paymill/api/php/payment.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 26, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
References
3forge.typo3.org
https://forge.typo3.org/issues/79325 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-5963