Medium severity6.1NVD Advisory· Published Dec 7, 2017· Updated Jun 17, 2026
CVE-2017-16884
CVE-2017-16884
Description
Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web script or HTML via vectors related to failed authentication requests alerts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:mistserver:mistserver:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mistserver:mistserver:*:*:*:*:*:*:*:*range: <2.13
- (no CPE)range: <2.13
Patches
Vulnerability mechanics
References
5- hyp3rlinx.altervista.org/advisories/MIST-SERVER-v2.12-UNAUTHENTICATED-PERSISTENT-XSS-CVE-2017-16884.txtnvdExploitThird Party Advisory
- packetstormsecurity.com/files/145182/MistServer-2.12-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2017/Dec/2nvdExploitMailing ListThird Party Advisory
- www.exploit-db.com/exploits/43205/nvdExploitThird Party AdvisoryVDB Entry
- news.mistserver.org/news/78/Stable+release+2.13+now+available%21nvdRelease Notes
News mentions
0No linked articles in our index yet.