CVE Feed

    Dashboard / CVE / CVE-2017-12439

    CVE-2017-12439

    SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-supplied input, in conjunction with an unsafe XML configuration file. This has resultant content forgery, cross site scripting, and unvalidated redirection issues.

    Published:Aug 5, 2017
    Last Modified:Apr 20, 2025
    EPS:Aug 5, 2017
    EPSS Score:0.00173
    CVSS Score:7.5

    Affected Products

    Vendor
    Socusoft
    Product
    Flash Slideshow Maker

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High