CVE-2017-9786

Source
https://cve.org/CVERecord?id=CVE-2017-9786
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9786.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-9786
Published
2018-03-06T16:29:00.590Z
Modified
2026-08-07T15:18:37.058640Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the Description field in My account Name updated, related to home.php and actions-log.php.

References

Affected packages

Git / github.com/projectsend/projectsend

Affected ranges

Type
GIT
Repo
https://github.com/projectsend/projectsend
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:projectsend:projectsend:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "r754"
        }
    ]
}

Affected versions

Other
r559
r753
r754

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9786.json"