Skip to main content

CVE detail

CVE-2017-9251

andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the sitename parameter to admin.php.

CVSS 6.1 · Medium