CVE-2017-9786

Source
https://cve.org/CVERecord?id=CVE-2017-9786
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9786.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-9786
Published
2018-03-06T16:29:00Z
Modified
2026-08-07T15:18:37Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the Description field in My account Name updated, related to home.php and actions-log.php.

References

Affected packages

Git / github.com/projectsend/projectsend

Affected ranges

Type
GIT
Repo
https://github.com/projectsend/projectsend
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "cpe": "cpe:2.3:a:projectsend:projectsend:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "r754"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

Other
r559
r753
r754

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-9786.json"