PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-6479 Fenix Hosting CVE debrief

CVE-2017-6479 describes a reflected cross-site scripting issue in Fenix Hosting's fenix-open-source application, affecting forums/search.php and the search-by-topic parameter. The CVE was published on 2017-03-05. NVD classifies the weakness as CWE-79 and assigns a CVSS 3.0 vector of AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, which means exploitation is possible over the network, requires no privileges, but does require user interaction. The supplied corpus indicates a vulnerable range ending at 2017-02-21, while the description says versions before 2017-03-04 are affected; treat those dates as source-specific and verify against the vendor's fix history.

Vendor
Fenix Hosting
Product
Fenix-Open-Source
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2017-03-05
Original CVE updated
2026-05-13
Advisory published
2017-03-05
Advisory updated
2026-05-13

Who should care

Administrators and maintainers of Fenix Hosting fenix-open-source deployments, especially any public forums/search.php endpoint exposed to untrusted users. Security teams responsible for web application hardening and browser-side risk reduction should also review affected instances.

Technical summary

The flaw is a reflected XSS in forums/search.php driven by the search-by-topic parameter. NVD maps it to CWE-79 and lists CVSS 3.0 AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The corpus shows the issue affecting fenix-open-source builds in the pre-fix range cited by the description and NVD CPE data.

Defensive priority

Medium priority. Reflected XSS can expose user-controlled browser context or trigger unwanted actions, but it depends on a victim following a crafted request and interacting with the affected page.

Recommended defensive actions

  • Identify all fenix-open-source deployments and confirm whether they fall within the vulnerable version range cited in the source corpus.
  • Upgrade to a vendor-fixed release or otherwise remove or disable the affected code path if an official fix is not available.
  • Review forums/search.php input handling and ensure search-by-topic output is contextually encoded before rendering.
  • Validate that reverse proxy, WAF, or application-layer controls do not hide the vulnerable endpoint during testing.
  • Add regression tests for reflected XSS on search endpoints and monitor logs for unexpected script-bearing parameters.

Evidence notes

The CVE description states: 'FenixHosting/fenix-open-source before 2017-03-04 is vulnerable to a reflected XSS in forums/search.php (search-by-topic parameter).' NVD records the weakness as CWE-79 and includes a vulnerable CPE range ending in 2017-02-21. The supplied references include SecurityFocus BID 96587 and a GitHub issue tagged as Exploit and Vendor Advisory. No KEV entry is present in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-6479 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-6479

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-6479 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6479

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.