Ubiquiti UCRM versions 2.5.0 to 2.7.7 are vulnerable to Stored Cross-site Scripting. Due to the lack sanitization, it is possible to inject arbitrary HTML code by manipulating the uploaded filename. Successful exploitation requires valid credentials to an account with "Edit" access to "Scheduling".
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2018-05-24T00:00:00

Updated: 2018-07-03T20:57:01

Reserved: 2016-11-30T00:00:00


Link: CVE-2017-0912

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-07-03T21:29:00.217

Modified: 2019-09-13T17:54:30.640


Link: CVE-2017-0912

JSON object: View

cve-icon Redhat Information

No data.

CWE