CVE-2017-11725
UnknownEPSS 0.57%
Last modified
CVE-2017-11725 is a vulnerability of currently unknown severity. The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Thycotic | Secret Server | <= 10.2.000018 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-11725?
The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.
How severe is CVE-2017-11725?
Severity scoring for CVE-2017-11725 is pending analysis. The EPSS model estimates a 0.57% probability of exploitation in the next 30 days.
How do I fix CVE-2017-11725?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-11719The dnxhd_decode_header function in libavcodec/dnxhddec.c in…
- CVE-2017-11720There is a division-by-zero vulnerability in LAME 3.99.5, ca…
- CVE-2017-11721Buffer overflow in ioquake3 before 2017-08-02 allows remote …
- CVE-2017-11722The WriteOnePNGImage function in coders/png.c in GraphicsMag…
- CVE-2017-11723Directory traversal vulnerability in plugins/ImageManager/ba…
- CVE-2017-11724The ReadMATImage function in coders/mat.c in ImageMagick thr…
- CVE-2017-11726services/system_io/actionprocessor/System.rails in ConnectWi…
- CVE-2017-11727services/system_io/actionprocessor/Contact.rails in ConnectW…
- CVE-2017-11728A heap-based buffer over-read was found in the function OpCo…
- CVE-2017-11729A heap-based buffer over-read was found in the function OpCo…
- CVE-2017-11730A heap-based buffer over-read was found in the function OpCo…
- CVE-2017-11731An invalid memory read vulnerability was found in the functi…
Are you affected by CVE-2017-11725?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
