CVE-2017-5631 EXPLOIT
6.1
MEDIUM · CVSS 3.0 · EPSS 4.5% (pctl 91)
Patch early
A public exploit exists.
Description
An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the login.php query string.
Scoring
| CVSS | 6.1 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 4.49% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-05-01 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| kmc information systems | caseaware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | KMCIS CaseAware - Cross-Site Scripting | 2017-05-20 |
References
→ the Explorer · watch your stack · NVD