Medium severity6.1OSV Advisory· Published Mar 15, 2017· Updated May 13, 2026
CVE-2017-6906
CVE-2017-6906
Description
An issue was discovered in SiberianCMS before 4.10.0. The vulnerability exists due to insufficient filtration of user-supplied data (log) passed to the "SiberianCMS-master/errors/500.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3v4.1.0, v4.1.1, v4.1.10, …+ 1 more
- (no CPE)range: v4.1.0, v4.1.1, v4.1.10, …
- (no CPE)range: <4.10.0
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/96898nvdThird Party AdvisoryVDB Entry
- github.com/Xtraball/SiberianCMS/issues/217nvd
News mentions
0No linked articles in our index yet.