CVE-2017-9306
Dashboard / Vulnerabilities / CVE-2017-9306
CVE-2017-9306
Published: 31 May 2017Last Modified: 8 Jul 2026
Summary:
Details: inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" substring instead of an "<svg onload=" substring.
References: https://www.cdxy.me/?p=763
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 0a63fc30b95d5ccc3c8397d05c2098c9b557dd3d
Fixed -None
Affected versions
2.1.9
2.1.9.17050401
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
