CVE-2017-15287: Bouqueteditor Project Bouqueteditor

Medium severity, CVSS 6.1. EPSS: 6.1% chance of exploitation in the next 30 days.

There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouquets" field, or the file parameter to the /file URI.

Affected products

Published 2017-10-12. Last modified 2026-06-17.