PatchSiren cyber security CVE debrief
CVE-2017-6491 Epesi CVE debrief
CVE-2017-6491 is a medium-severity cross-site scripting issue in EPESI 1.8.1.1. According to the official NVD record, multiple user-controlled parameters passed to the Tooltip req.php endpoint were not filtered sufficiently, allowing an attacker to inject HTML or script that would run in the context of the vulnerable website.
- Vendor
- Epesi
- Product
- Unknown
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-05
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-05
- Advisory updated
- 2026-05-13
Who should care
Organizations running EPESI 1.8.1.1, especially teams responsible for web application security, application administration, and user-facing portals where browsers may process untrusted input.
Technical summary
The NVD record maps this issue to CWE-79 and identifies EPESI 1.8.1.1 as vulnerable. The affected surface is the EPESI-master/modules/Utils/Tooltip/req.php URL, where parameters including tooltip_id, callback, args, and cid were insufficiently validated or filtered. The impact is browser-side script execution in the origin of the application, with CVSS v3.1 AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.
Defensive priority
Medium. Prioritize remediation if EPESI is internet-facing, used by many users, or processes sensitive session data, since reflected or stored script execution in the application origin can expose user data and enable account abuse.
Recommended defensive actions
- Confirm whether EPESI 1.8.1.1 is deployed anywhere in the environment, including legacy or test instances.
- Apply the vendor fix or patched version referenced by the EPESI issue tracker entry linked from the CVE record.
- Review any custom integrations or templates that call the Tooltip req.php endpoint and ensure untrusted input is not passed through unsanitized.
- Use output encoding and server-side validation for any data that reaches browser-rendered content.
- Add monitoring and filtering for suspicious requests targeting the Tooltip req.php endpoint and its parameters.
- Limit exposure of the application to trusted users where possible until remediation is complete.
Evidence notes
This debrief is based only on the official NVD CVE record and the linked references supplied in the source corpus. The NVD metadata identifies EPESI 1.8.1.1 as the vulnerable CPE, classifies the weakness as CWE-79, and lists the affected parameters and endpoint in the CVE description. The referenced EPESI GitHub issue is tagged by the CVE source as both Exploit and Patch, but this summary does not rely on any unverified exploit details.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-6491 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-6491
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-6491 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6491
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/Telaxus/EPESI/issues/168
[email protected] - Exploit, Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.