icon

We found results for “

WS-2017-3739

Good to know:

icon

Date: November 14, 2017

An XSS vulnerability found in Symphony before 2.3.0. The HTTP input validation was filtering only right angle brackets but other special characters could be inserted.

Language: Java

Severity Score

Severity Score

Weakness Type (CWE)

Input Validation

CWE-20

Top Fix

icon

Upgrade Version

Upgrade to version https://github.com/b3log/symphony/commit/3996cea010eae434682656d46afd305efd65447c

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us