CVE-2017-15287: Bouqueteditor Project Bouqueteditor
Medium severity, CVSS 6.1. EPSS: 6.1% chance of exploitation in the next 30 days.
There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouquets" field, or the file parameter to the /file URI.
Affected products
- Bouqueteditor Project Bouqueteditor: version 2.0.0 only
Published 2017-10-12. Last modified 2026-06-17.