ZeroHour

CVE-2017-1000236

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p56
Published
()
Modified
Description

I, Librarian version <=4.6 & 4.7 is vulnerable to Reflected Cross-Site Scripting in the temp.php resulting in an attacker being able to inject malicious client side scripting which will be executed in the browser of users if they visit the manipulated site.

Vendors
scilico
Products
i\, librarian
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.