CVE-2017-17055: Articatech Artica Proxy

Critical severity, CVSS 9.0. EPSS: 8.7% chance of exploitation in the next 30 days.

Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id parameter to freeradius.users.php.

Affected products

  • Articatech Artica Proxy: before 3.06.112911 (fixed in 3.06.112911)

Published 2017-12-07. Last modified 2026-06-17.