PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-6491 Epesi CVE debrief

CVE-2017-6491 is a medium-severity cross-site scripting issue in EPESI 1.8.1.1. According to the official NVD record, multiple user-controlled parameters passed to the Tooltip req.php endpoint were not filtered sufficiently, allowing an attacker to inject HTML or script that would run in the context of the vulnerable website.

Vendor
Epesi
Product
Unknown
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2017-03-05
Original CVE updated
2026-05-13
Advisory published
2017-03-05
Advisory updated
2026-05-13

Who should care

Organizations running EPESI 1.8.1.1, especially teams responsible for web application security, application administration, and user-facing portals where browsers may process untrusted input.

Technical summary

The NVD record maps this issue to CWE-79 and identifies EPESI 1.8.1.1 as vulnerable. The affected surface is the EPESI-master/modules/Utils/Tooltip/req.php URL, where parameters including tooltip_id, callback, args, and cid were insufficiently validated or filtered. The impact is browser-side script execution in the origin of the application, with CVSS v3.1 AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.

Defensive priority

Medium. Prioritize remediation if EPESI is internet-facing, used by many users, or processes sensitive session data, since reflected or stored script execution in the application origin can expose user data and enable account abuse.

Recommended defensive actions

  • Confirm whether EPESI 1.8.1.1 is deployed anywhere in the environment, including legacy or test instances.
  • Apply the vendor fix or patched version referenced by the EPESI issue tracker entry linked from the CVE record.
  • Review any custom integrations or templates that call the Tooltip req.php endpoint and ensure untrusted input is not passed through unsanitized.
  • Use output encoding and server-side validation for any data that reaches browser-rendered content.
  • Add monitoring and filtering for suspicious requests targeting the Tooltip req.php endpoint and its parameters.
  • Limit exposure of the application to trusted users where possible until remediation is complete.

Evidence notes

This debrief is based only on the official NVD CVE record and the linked references supplied in the source corpus. The NVD metadata identifies EPESI 1.8.1.1 as the vulnerable CPE, classifies the weakness as CWE-79, and lists the affected parameters and endpoint in the CVE description. The referenced EPESI GitHub issue is tagged by the CVE source as both Exploit and Patch, but this summary does not rely on any unverified exploit details.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-6491 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-6491

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-6491 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6491

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.