← back
CVE-2017-5631

CVE-2017-5631

38Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 4.5%
from disclosure to weapon19 days
Published on NVDMay 1
1st PoC+19d
exploitation probability
4.5%top 9% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the login.php query string.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.