AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-2674

MEDIUM · CVSS 6.1 EPSS 1.29%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-07-27 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2017-2674
Severity
MEDIUM
CVSS
6.1
EPSS
1.29%

Original NVD Description

JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation of user input when creating new lists. Remote, authenticated attackers that have privileges to create lists can store scripts in them, which are not properly sanitized before showing to other users, including admins.