PatchSiren

Nagvis CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Nagvis CVE published 2017-03-02

CVE-2017-6393

CVE-2017-6393 is a cross-site scripting issue in NagVis 1.9b12. The supplied NVD record says insufficient filtration of user-supplied data passed to the "nagvis-master/share/userfiles/gadgets/std_table.php" URL can let an attacker execute arbitrary HTML and script code in a browser in the context of the vulnerable website. NVD classifies the issue as CWE-79 and rates it CVSS 6.1 (medium), with network att [truncated]