{"id":"CVE-2017-5961","details":"An issue was discovered in ionize through 1.0.8. The vulnerability exists due to insufficient filtration of user-supplied data in the \"path\" HTTP GET parameter passed to the \"ionize-master/themes/admin/javascript/tinymce/jscripts/tiny_mce/plugins/codemirror/dialog.php\" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.","modified":"2026-07-08T12:28:05.485123Z","published":"2017-02-12T04:59:00.207Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/96196"},{"type":"FIX","url":"https://github.com/ionize/ionize/issues/393"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ionize/ionize","events":[{"introduced":"0"},{"last_affected":"abdad5d80ea9bf1a0bef57e3273456c5fc62a24c"}],"database_specific":{"cpe":"cpe:2.3:a:ionizecms:ionize:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.0.8"}],"source":"CPE_RANGE"}}],"versions":["1.0.8","1.0.7.1","1.0.7","1.0.6","1.0.5.2","1.0.5.1","1.0.5","1.0.4","1.0.3","1.0.2","1.0.1","1.0.0","0.9.9.5","0.9.9.4","0.9.9.3","0.9.9.2","0.9.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5961.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}