Record summary

CVE-2017-7188 has a selected CVSS score of 5.4 (medium); EIP currently links 1 repository PoC.

Description

Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

Proofs of concept

1

Repository PoCs

GitHubfaizzaidi/Zurmo-Stable-3.1.1-XSS-By-Provensec-LLCRepository PoCby faizzaidiStars: 2Not analyzed2 files

140.0 KiB

GitHub

PoC details

References

4