AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-5246

MEDIUM · CVSS 4.3 EPSS 0.60%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-07-18 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2017-5246
Severity
MEDIUM
CVSS
4.3
EPSS
0.60%

Original NVD Description

Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a valid AngularJS expression, wrapped in double curly-braces ({{ }}). This expression will be evaluated by any other authenticated user who views the attacker's display name. Affected versions are 5.0.0000 through 5.1.1026. The Issue is fixed in 5.1.1028.