CVE-2017-5246
Last modified
CVE-2017-5246 is a vulnerability of currently unknown severity. Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a valid AngularJS expression, wrapped in double curly-braces ({{ }}). EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a valid AngularJS expression, wrapped in double curly-braces ({{ }}). This expression will be evaluated by any other authenticated user who views the attacker's display name. Affected versions are 5.0.0000 through 5.1.1026. The Issue is fixed in 5.1.1028.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Biscom | Secure File Transfer | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-5246?
How severe is CVE-2017-5246?
How do I fix CVE-2017-5246?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-5240Editions of Rapid7 AppSpider Pro prior to version 6.14.060 c…
- CVE-2017-5241Biscom Secure File Transfer versions 5.0.0.0 trough 5.1.1024…
- CVE-2017-5242Nexpose and InsightVM virtual appliances downloaded between …7.7
- CVE-2017-5243The default SSH configuration in Rapid7 Nexpose hardware app…
- CVE-2017-5244Routes used to stop running Metasploit tasks (either particu…
- CVE-2017-5245Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-5247Biscom Secure File Transfer is vulnerable to cross-site scri…
- CVE-2017-5249In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Ho…
- CVE-2017-5250In version 1.9.7 and prior of Insteon's Insteon for Hub Andr…
- CVE-2017-5251In version 1012 and prior of Insteon's Insteon Hub, the radi…
- CVE-2017-5254In version 3.5 and prior of Cambium Networks ePMP firmware, …
- CVE-2017-5255In version 3.5 and prior of Cambium Networks ePMP firmware, …
Are you affected by CVE-2017-5246?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
