CVE-2017-9783 describes a cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) versions prior to commit 6c3710430be26feb5371cb0377e5355d6f9a27ca. This medium-severity flaw (CVSS 6.1) allows unauthenticated remote attackers to inject arbitrary web script or HTML through the "Description" field when updating a site name, requiring user interaction. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= r754CPE matchmatch criteria | cpe:2.3:a:projectsend:projectsend:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.