CVE-2017-5246
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
18/07/2017
Last modified:
20/04/2025
Description
Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a valid AngularJS expression, wrapped in double curly-braces ({{ }}). This expression will be evaluated by any other authenticated user who views the attacker's display name. Affected versions are 5.0.0000 through 5.1.1026. The Issue is fixed in 5.1.1028.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:biscom:secure_file_transfer:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page