peter bassill · operator
$ cve CVE-2017-5631 JSON

CVE-2017-5631 EXPLOIT

6.1
MEDIUM · CVSS 3.0 · EPSS 4.5% (pctl 91)

Patch early

A public exploit exists.

Description

An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the login.php query string.

Scoring

CVSS6.1 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS4.49% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2017-05-01
Last modified2026-06-17

Affected (1)

VendorProduct
kmc information systemscaseaware

Public exploits

SourceTitleDate
exploit-dbKMCIS CaseAware - Cross-Site Scripting2017-05-20

References

→ the Explorer  ·  watch your stack  ·  NVD