CVE Database
/

CVE-2017-2171

Back to search

CVE-2017-2171

Published: May 22, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2, Custom Search prior to version 1.36, Donate prior to version 2.1.1, Email Queue prior to version 1.1.2, Error Log Viewer prior to version 1.0.6, Facebook Button prior to version 2.54, Featured Posts prior to version 1.0.1, Gallery Categories prior to version 1.0.9, Gallery prior to version 4.5.0, Google +1 prior to version 1.3.4, Google AdSense prior to version 1.44, Google Analytics prior to version 1.7.1, Google Captcha (reCAPTCHA) prior to version 1.28, Google Maps prior to version 1.3.6, Google Shortlink prior to version 1.5.3, Google Sitemap prior to version 3.0.8, Htaccess prior to version 1.7.6, Job Board prior to version 1.1.3, Latest Posts prior to version 0.3, Limit Attempts prior to version 1.1.8, LinkedIn prior to version 1.0.5, Multilanguage prior to version 1.2.2, PDF & Print prior to version 1.9.4, Pagination prior to version 1.0.7, Pinterest prior to version 1.0.5, Popular Posts prior to version 1.0.5, Portfolio prior to version 2.4, Post to CSV prior to version 1.3.1, Profile Extra prior to version 1.0.7. PromoBar prior to version 1.1.1, Quotes and Tips prior to version 1.32, Re-attacher prior to version 1.0.9, Realty prior to version 1.1.0, Relevant - Related Posts prior to version 1.2.0, Sender prior to version 1.2.1, SMTP prior to version 1.1.0, Social Buttons Pack prior to version 1.1.1, Subscriber prior to version 1.3.5, Testimonials prior to version 0.1.9, Timesheet prior to version 0.1.5, Twitter Button prior to version 2.55, User Role prior to version 1.5.6, Updater prior to version 1.35, Visitors Online prior to version 1.0.0, and Zendesk Help Center prior to version 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the function to display the BestWebSoft menu.

VendorProductVersions

BestWebSoft

Captcha

affected
prior to version 4.3.0

BestWebSoft

Car Rental

affected
prior to version 1.0.5

BestWebSoft

Contact Form Multi

affected
prior to version 1.2.1

BestWebSoft

Contact Form

affected
prior to version 4.0.6

BestWebSoft

Contact Form to DB

affected
prior to version 1.5.7

BestWebSoft

Custom Admin Page

affected
prior to version 0.1.2

BestWebSoft

Custom Fields Search

affected
prior to version 1.3.2

BestWebSoft

Custom Search

affected
prior to version 1.36

BestWebSoft

Donate

affected
prior to version 2.1.1

BestWebSoft

Email Queue

affected
prior to version 1.1.2

BestWebSoft

Error Log Viewer

affected
prior to version 1.0.6

BestWebSoft

Facebook Button

affected
prior to version 2.54

BestWebSoft

Featured Posts

affected
prior to version 1.0.1

BestWebSoft

Gallery Categories

affected
prior to version 1.0.9

BestWebSoft

Gallery

affected
prior to version 4.5.0

BestWebSoft

Google +1

affected
prior to version 1.3.4

BestWebSoft

Google AdSense

affected
prior to version 1.44

BestWebSoft

Google Analytics

affected
prior to version 1.7.1

BestWebSoft

Google Captcha (reCAPTCHA)

affected
prior to version 1.28

BestWebSoft

Google Maps

affected
prior to version 1.3.6

BestWebSoft

Google Shortlink

affected
prior to version 1.5.3

BestWebSoft

Google Sitemap

affected
prior to version 3.0.8

BestWebSoft

Htaccess

affected
prior to version 1.7.6

BestWebSoft

Job Board

affected
prior to version 1.1.3

BestWebSoft

Latest Posts

affected
prior to version 0.3

BestWebSoft

Limit Attempts

affected
prior to version 1.1.8

BestWebSoft

LinkedIn

affected
prior to version 1.0.5

BestWebSoft

Multilanguage

affected
prior to version 1.2.2

BestWebSoft

PDF & Print

affected
prior to version 1.9.4

BestWebSoft

Pagination

affected
prior to version 1.0.7

BestWebSoft

Pinterest

affected
prior to version 1.0.5

BestWebSoft

Popular Posts

affected
prior to version 1.0.5

BestWebSoft

Portfolio

affected
prior to version 2.4

BestWebSoft

Post to CSV

affected
prior to version 1.3.1

BestWebSoft

Profile Extra

affected
prior to version 1.0.7

BestWebSoft

PromoBar

affected
prior to version 1.1.1

BestWebSoft

Quotes and Tips

affected
prior to version 1.32

BestWebSoft

Re-attacher

affected
prior to version 1.0.9

BestWebSoft

Realty

affected
prior to version 1.1.0

BestWebSoft

Relevant - Related Posts

affected
prior to version 1.2.0

BestWebSoft

Sender

affected
prior to version 1.2.1

BestWebSoft

SMTP

affected
prior to version 1.1.0

BestWebSoft

Social Buttons Pack

affected
prior to version 1.1.1

BestWebSoft

Subscriber

affected
prior to version 1.3.5

BestWebSoft

Testimonials

affected
prior to version 0.1.9

BestWebSoft

Timesheet

affected
prior to version 0.1.5

BestWebSoft

Twitter Button

affected
prior to version 2.55

BestWebSoft

User Role

affected
prior to version 1.5.6

BestWebSoft

Updater

affected
prior to version 1.35

BestWebSoft

Visitors Online

affected
prior to version 1.0.0

BestWebSoft

Zendesk Help Center

affected
prior to version 1.0.5

References

JVNDB-2017-000094
third-party-advisory
x_refsource_JVNDB
JVN#24834813
third-party-advisory
x_refsource_JVN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now