CVE-2017-9621
MEDIUMTelaxus/EPESI <1.8.2 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in modules/Base/Lang/Administrator/update_translation.php in EPESI in Telaxus/EPESI 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) original or (2) new parameter.
Scores
CVSS v3
6.1
EPSS
0.0040
EPSS Percentile
60.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
epesi/epesi
< 1.8.2
n/a/n/a
Published
Jun 14, 2017
Tracked Since
Feb 18, 2026