CVE-2007-3017
The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent
The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wysiwyg/rendereditor.asp, which allows remote authenticated users to inject arbitrary JavaScript via a request to admin/worklist/worklist_edit.asp.
MEDIUM · CVSS 4
EPSS 0.09007
Schedule remediation
- EPSS percentile: top 7% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
Sigma rules0
YARA rules0