CVE-2017-8302
MEDIUMBlueriver Muracms - XSS
Title source: ruleDescription
Mura CMS 7.0.6967 allows admin/?muraAction= XSS attacks, related to admin/core/views/carch/list.cfm, admin/core/views/carch/loadsiteflat.cfm, admin/core/views/cusers/inc/dsp_nextn.cfm, admin/core/views/cusers/inc/dsp_search_form.cfm, admin/core/views/cusers/inc/dsp_users_list.cfm, admin/core/views/cusers/list.cfm, and admin/core/views/cusers/listusers.cfm.
Scores
CVSS v3
5.4
EPSS
0.0021
EPSS Percentile
42.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (2)
blueriver/muracms
n/a/n/a
Timeline
Published
Apr 27, 2017
Tracked Since
Feb 18, 2026