ZeroHour

CVE-2017-8892

PoC
CVSS 3.0
6.1 medium
EPSS
<1%p58
Published
()
Modified
Description

Cross-site scripting (XSS) vulnerability in OpenText Tempo Box 10.0.3 allows remote attackers to inject arbitrary web script or HTML persistently via the name of an uploaded image.

Vendors
opentext
Products
tempo box
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.