XSS Vulnerability in PivotX 2.3.11 via Smarty Self Function

XSS Vulnerability in PivotX 2.3.11 via Smarty Self Function

CVE-2017-9332 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the self Smarty tag.

Learn more about our Web Application Penetration Testing UK.