CVE-2017-6511

Publication date

2017-03-07 19:00:00

Family

mitre

State

PUBLISHED

Description

andrzuk/FineCMS before 2017-03-06 is vulnerable to a reflected XSS in index.php because of missing validation of the action parameter in application/classes/application.php.