CVE-2017-7276

CVSS V2 Medium 4.3 CVSS V3 Medium 6.1
Description
There is reflected XSS in TOPdesk before 5.7.6 and 6.x and 7.x before 7.03.019.
Overview
  • CVE ID
  • CVE-2017-7276
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2017-07-04T18:29:00
  • Last Modified Date
  • 2017-07-20T16:42:45
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:topdesk:topdesk:*:*:*:*:*:*:*:* 1 OR 5.7.5
cpe:2.3:a:topdesk:topdesk:6.04.001:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.04.005:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.04.006:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.04.008:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.04.011:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.04.012:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.04.013:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.04.015:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.04.016:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.05.002:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.05.006:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.05.007:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.05.008:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.05.009:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.05.010:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.05.016:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.05.017:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.06.002:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.06.003:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.06.004:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.06.005:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.06.006:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.06.007:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.06.013:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.06.014:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.06.020:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.07.002:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.07.005:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.07.007:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.07.010:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.07.014:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.07.019:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.07.022:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.07.023:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.08.001:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.08.011:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.08.016:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.08.020:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.08.021:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.08.024:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.08.025:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.08.029:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.08.030:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.08.031:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.08.033:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.08.034:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.09.001:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.09.005:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.09.010:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.09.011:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.09.012:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.09.013:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.09.014:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.09.015:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.09.017:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.09.018:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.09.019:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.09.021:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.09.022:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.09.023:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.09.024:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.10.008:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.10.015:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.10.021:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.10.022:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.10.025:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.10.026:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.10.027:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.10.037:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.10.040:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.11.003:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.11.015:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.11.024:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.11.030:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.12.006:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.12.007:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.12.008:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.12.013:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.12.015:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.12.020:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.12.022:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.12.025:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:6.12.026:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.01.001:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.01.008:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.01.020:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.01.024:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.02.012:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.02.013:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.02.014:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.02.016:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.02.021:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.03.007:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.03.008:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.03.018:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.03.019:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.03.020:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.03.022:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.04.001:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.04.004:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.04.019:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.04.021:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.04.023:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.05.006:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.05.007:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.05.020:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.05.023:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.06.001:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.06.005:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.06.010:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.06.011:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:topdesk:topdesk:7.06.014:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
  • Access Vector
  • NETWORK
  • Access Compatibility
  • MEDIUM
  • Authentication
  • NONE
  • Confidentiality Impact
  • NONE
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • NONE
  • Base Score
  • 4.3
  • Severity
  • MEDIUM
  • Exploitability Score
  • 8.6
  • Impact Score
  • 2.9
CVSS Version 3
  • Version
  • 3.0
  • Vector String
  • CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • REQUIRED
  • Scope
  • CHANGED
  • Confidentiality Impact
  • LOW
  • Availability Impact
  • NONE
  • Base Score
  • 6.1
  • Base Severity
  • MEDIUM
  • Exploitability Score
  • 2.8
  • Impact Score
  • 2.7
References
Reference URL Reference Tags
http://page.topdesk.com/cve-2017-7276 Vendor Advisory
History
Created Old Value New Value Data Type Notes
2022-05-10 09:18:40 Added to TrackCVE
2022-12-02 18:15:54 2017-07-04T18:29Z 2017-07-04T18:29:00 CVE Published Date updated
2022-12-02 18:15:54 2017-07-20T16:42:45 CVE Modified Date updated
2022-12-02 18:15:54 Analyzed Vulnerability Status updated