{"id":"CVE-2017-6908","details":"An issue was discovered in concrete5 \u003c= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (fID) passed to the \"concrete5-legacy-master/web/concrete/tools/files/selector_data.php\" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.","modified":"2026-08-27T08:18:39.287863Z","published":"2017-03-15T00:59:00.253Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/96891"},{"type":"FIX","url":"https://github.com/concrete5/concrete5-legacy/commit/62046f511fc02ad783ad170404c80db3c69f0408"},{"type":"EVIDENCE","url":"https://github.com/concrete5/concrete5-legacy/issues/1948"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/concretecms/concrete5-legacy","events":[{"introduced":"0"},{"last_affected":"629e95fd4ccfd63f7bd2444e8e77faa8f0b432c4"},{"fixed":"62046f511fc02ad783ad170404c80db3c69f0408"}],"database_specific":{"cpe":"cpe:2.3:a:concrete5:concrete5:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"5.6.3.3"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["5.6.3.4","5.6.3.3","5.6.3.2","5.6.3.1","5.6.3","5.6.2.1","5.6.2","5.6.1.2","5.6.1.1","5.6.1","5.6.0.1","5.6.0.2","5.6.0","5.5.2.1","5.5.2","5.5.1","5.5.0","5.4.2.2","5.4.2.1","5.4.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-6908.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}