VYPR
Unrated severityNVD Advisory· Published May 10, 2019· Updated Aug 5, 2024

CVE-2017-12885

CVE-2017-12885

Description

OX Software GmbH App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

OX App Suite 7.8.4 and earlier is vulnerable to cross-site scripting (XSS), allowing an attacker to inject arbitrary web scripts.

Vulnerability

OX Software GmbH App Suite versions 7.8.4 and earlier are affected by a cross-site scripting (XSS) vulnerability [1]. The exact component and input vector are not detailed in the available references, but the issue allows injection of malicious scripts into the application.

Exploitation

An attacker could exploit this XSS by crafting a malicious payload and delivering it to a user, likely via a crafted link or by injecting script into a field that is later rendered. No authentication or special network position is specified; the vulnerability may be exploitable remotely without authentication if the application does not properly sanitize user input.

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's session. This could lead to session hijacking, data theft, or defacement. The impact is limited to the privileges of the affected user.

Mitigation

The vendor has not explicitly disclosed a fix for this CVE in the provided reference [1]. Users should upgrade to a version beyond 7.8.4, as later releases likely contain a patch. The release notes for 7.8.3 list many fixes but do not mention this specific CVE. If no patch is available, consider applying input validation and output encoding as a workaround.

References
  1. ReleaseNotes

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.