Vulnerabilities > Bouqueteditor Project > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-10-12 CVE-2017-15287 Cross-site Scripting vulnerability in Bouqueteditor Project Bouqueteditor 2.0.0
There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouquets" field, or the file parameter to the /file URI.
4.3