← Back

CVE-2017-1000236

nvd nist
Published: Nov 17, 2017Modified: Dec 5, 2025

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

I, Librarian version <=4.6 & 4.7 is vulnerable to Reflected Cross-Site Scripting in the temp.php resulting in an attacker being able to inject malicious client side scripting which will be executed in the browser of users if they visit the manipulated site.

Affected (2)

1 product
I, Librarian
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Scilico
Up to 4.6
Version 4.7

Timeline

No history available yet.