CVE-2017-20191
Last modified
CVE-2017-20191 is a low-severity vulnerability rated 3.5/10 on the CVSS scale. A vulnerability was found in Zimbra zm-admin-ajax up to 8.8.1. It has been classified as problematic. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Zimbra zm-admin-ajax up to 8.8.1. It has been classified as problematic. This affects the function XFormItem.prototype.setError of the file WebRoot/js/ajax/dwt/xforms/XFormItem.js of the component Form Textbox Field Error Handler. The manipulation of the argument message leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 8.8.2 is able to address this issue. The identifier of the patch is bb240ce0c71c01caabaa43eed30c78ba8d7d3591. It is recommended to upgrade the affected component. The identifier VDB-258621 was assigned to this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2017-20191?
How severe is CVE-2017-20191?
How do I fix CVE-2017-20191?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-20186** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in…7.5
- CVE-2017-20187** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in…9.8
- CVE-2017-20188A vulnerability has been found in Zimbra zm-ajax up to 8.8.1…4.7
- CVE-2017-20189In Clojure before 1.9.0, classes can be used to construct a …9.8
- CVE-2017-2019Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-20190Some Microsoft technologies as used in Windows 8 through 11 …
- CVE-2017-20192The Formidable Form Builder plugin for WordPress is vulnerab…6.1
- CVE-2017-20193The Product Vendors is vulnerable to Reflected Cross-Site Sc…6.1
- CVE-2017-20194The Formidable Form Builder plugin for WordPress is vulnerab…5.3
- CVE-2017-20195A vulnerability was found in LUNAD3v AreaLoad up to 1a110318…5.5
- CVE-2017-20196A vulnerability was found in Itechscripts School Management …6.3
- CVE-2017-20197A vulnerability was found in propanetank Roommate-Bill-Track…7.3
Are you affected by CVE-2017-20191?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
