PatchSiren

Sanadata CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Sanadata CVE published 2017-02-04

CVE-2017-5882

CVE-2017-5882 is a reflected cross-site scripting issue in SANADATA SanaCMS 7.3. According to the NVD record, the flaw is in index.asp and can be triggered through the search parameter, allowing a remote attacker to inject arbitrary web script or HTML. The issue was published on 2017-02-04 and is scored CVSS 6.1 (Medium).