CVE-2017-12439
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
05/08/2017
Last modified:
20/04/2025
Description
SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-supplied input, in conjunction with an unsafe XML configuration file. This has resultant content forgery, cross site scripting, and unvalidated redirection issues.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.10
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:socusoft:flash_slideshow_maker:*:*:*:*:*:*:*:* | 5.20 (including) |
To consult the complete list of CPE names with products and versions, see this page



