I, Librarian version <=4.6 & 4.7 is vulnerable to Reflected Cross-Site Scripting in the temp.php resulting in an attacker being able to inject malicious client side scripting which will be executed in the browser of users if they visit the manipulated site.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Dec 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Scilico
Scilico i\, Librarian |
|
| CPEs | cpe:2.3:a:i-librarian:i_librarian:4.7:*:*:*:*:*:*:* |
cpe:2.3:a:scilico:i\,_librarian:*:*:*:*:*:*:*:* cpe:2.3:a:scilico:i\,_librarian:4.7:*:*:*:*:*:*:* |
| Vendors & Products |
I-librarian
I-librarian i Librarian |
Scilico
Scilico i\, Librarian |
| Metrics |
cvssV3_0
|
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2017-11-17T04:00:00Z
Updated: 2024-09-17T03:22:42.978Z
Reserved: 2017-11-16T00:00:00Z
Link: CVE-2017-1000236
No data.
Status : Analyzed
Published: 2017-11-17T04:29:00.420
Modified: 2025-12-05T20:16:25.080
Link: CVE-2017-1000236
No data.