PatchSiren

Flightairmap CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Flightairmap CVE published 2017-03-02

CVE-2017-6397

CVE-2017-6397 is a medium-severity cross-site scripting vulnerability in FlightAirMap v1.0-beta.10. The affected application pages do not sufficiently filter multiple user-supplied parameters, allowing an attacker to inject HTML or script that runs in a victim’s browser in the context of the vulnerable website.