PatchSiren cyber security CVE debrief
CVE-2017-6479 Fenix Hosting CVE debrief
CVE-2017-6479 describes a reflected cross-site scripting issue in Fenix Hosting's fenix-open-source application, affecting forums/search.php and the search-by-topic parameter. The CVE was published on 2017-03-05. NVD classifies the weakness as CWE-79 and assigns a CVSS 3.0 vector of AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, which means exploitation is possible over the network, requires no privileges, but does require user interaction. The supplied corpus indicates a vulnerable range ending at 2017-02-21, while the description says versions before 2017-03-04 are affected; treat those dates as source-specific and verify against the vendor's fix history.
- Vendor
- Fenix Hosting
- Product
- Fenix-Open-Source
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-05
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-05
- Advisory updated
- 2026-05-13
Who should care
Administrators and maintainers of Fenix Hosting fenix-open-source deployments, especially any public forums/search.php endpoint exposed to untrusted users. Security teams responsible for web application hardening and browser-side risk reduction should also review affected instances.
Technical summary
The flaw is a reflected XSS in forums/search.php driven by the search-by-topic parameter. NVD maps it to CWE-79 and lists CVSS 3.0 AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The corpus shows the issue affecting fenix-open-source builds in the pre-fix range cited by the description and NVD CPE data.
Defensive priority
Medium priority. Reflected XSS can expose user-controlled browser context or trigger unwanted actions, but it depends on a victim following a crafted request and interacting with the affected page.
Recommended defensive actions
- Identify all fenix-open-source deployments and confirm whether they fall within the vulnerable version range cited in the source corpus.
- Upgrade to a vendor-fixed release or otherwise remove or disable the affected code path if an official fix is not available.
- Review forums/search.php input handling and ensure search-by-topic output is contextually encoded before rendering.
- Validate that reverse proxy, WAF, or application-layer controls do not hide the vulnerable endpoint during testing.
- Add regression tests for reflected XSS on search endpoints and monitor logs for unexpected script-bearing parameters.
Evidence notes
The CVE description states: 'FenixHosting/fenix-open-source before 2017-03-04 is vulnerable to a reflected XSS in forums/search.php (search-by-topic parameter).' NVD records the weakness as CWE-79 and includes a vulnerable CPE range ending in 2017-02-21. The supplied references include SecurityFocus BID 96587 and a GitHub issue tagged as Exploit and Vendor Advisory. No KEV entry is present in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-6479 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-6479
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-6479 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6479
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/FenixHosting/fenix-open-source/issues/2
[email protected] - Exploit, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.