Ubiquiti UCRM versions 2.5.0 to 2.7.7 are vulnerable to Stored Cross-site Scripting. Due to the lack sanitization, it is possible to inject arbitrary HTML code by manipulating the uploaded filename. Successful exploitation requires valid credentials to an account with "Edit" access to "Scheduling".
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2018-07-03T21:00:00Z

Updated: 2024-09-16T19:15:34.084Z

Reserved: 2016-11-30T00:00:00

Link: CVE-2017-0912

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-07-03T21:29:00.217

Modified: 2019-09-13T17:54:30.640

Link: CVE-2017-0912

cve-icon Redhat

No data.