CVE Published: 18/07/2017 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: rapid7 |
Vendor: Biscom |
Product: Secure File Transfer Status : PUBLISHED
CVE-2017-5246 Description
Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a valid AngularJS expression, wrapped in double curly-braces ({{ }}). This expression will be evaluated by any other authenticated user who views the attacker\'s display name. Affected versions are 5.0.0000 through 5.1.1026. The Issue is fixed in 5.1.1028.