PatchSiren cyber security CVE debrief
CVE-2017-6480 Groovel Project CVE debrief
CVE-2017-6480 describes a reflected cross-site scripting (XSS) vulnerability in groovel/cmsgroovel before 3.3.7-beta. The issue is in commons/browser.php and involves the path parameter, allowing attacker-controlled input to be reflected into a victim’s browser. Because exploitation requires user interaction, the risk is typically highest where users can be lured into opening a crafted link or visiting a malicious page.
- Vendor
- Groovel Project
- Product
- Cmsgroovel
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-05
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-05
- Advisory updated
- 2026-05-13
Who should care
Administrators, developers, and security teams running groovel/cmsgroovel versions earlier than 3.3.7-beta should treat this as relevant. It is especially important for any deployment where users can access the affected browser endpoint over the network.
Technical summary
NVD classifies the issue as CWE-79 (Improper Neutralization of Input During Web Page Generation) with a CVSS 3.0 vector of AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The vulnerable surface is commons/browser.php, where the path parameter can be reflected in a way that enables script execution in the context of the victim’s session. NVD’s vulnerable version range indicates affected cmsgroovel builds up to and including 3.3.6, with 3.3.7-beta referenced as the fixed release.
Defensive priority
Medium
Recommended defensive actions
- Upgrade groovel/cmsgroovel to 3.3.7-beta or a later fixed release referenced by the vendor.
- Review commons/browser.php for unsafe reflection of the path parameter and apply strict output encoding.
- Add server-side input validation and context-aware output escaping for any user-controlled values rendered into HTML.
- Check application logs and web access logs for suspicious requests targeting commons/browser.php, especially crafted path values.
- If immediate patching is not possible, restrict exposure of the affected application to trusted users and networks until remediation is complete.
Evidence notes
The official NVD entry identifies this as CVE-2017-6480, maps it to CWE-79, and lists the vulnerable cpe range through version 3.3.6. The MITRE-cited vendor references point to a GitHub issue and the 3.3.7-beta release notes, supporting the remediation version and the affected component path. The CVSS vector indicates network reachability but requires user interaction, consistent with reflected XSS behavior.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-6480 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-6480
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-6480 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6480
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/groovel/cmsgroovel/issues/2
[email protected] - Exploit, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/groovel/cmsgroovel/releases/tag/3.3.7-beta
[email protected] - Release Notes, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.