{"id":"GHSA-pwr7-j6g3-hmx6","summary":"GeniXCMS XSS Vulnerability","details":"GeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter. NOTE: this might overlap CVE-2017-14761, CVE-2017-14762, or CVE-2017-14765.","aliases":["CVE-2017-17431"],"modified":"2024-02-16T08:15:45.470012Z","published":"2022-05-17T00:11:38Z","database_specific":{"nvd_published_at":"2017-12-05T21:29:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-07-27T00:15:21Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-17431"},{"type":"WEB","url":"https://code610.blogspot.com/2017/12/modus-operandi-genixcms-115.html"},{"type":"PACKAGE","url":"https://github.com/semplon/GeniXCMS"}],"affected":[{"package":{"name":"genix/cms","ecosystem":"Packagist","purl":"pkg:composer/genix/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.1.5"}]}],"versions":["1.0.0","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-pwr7-j6g3-hmx6/GHSA-pwr7-j6g3-hmx6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}