CVE-2017-17911: Archon

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

packages/core/contact.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?p=core/contact request, aka Open Bug Bounty ID OBB-278503.

Affected products

  • Archon Archon: version 3.21 only

Published 2017-12-27. Last modified 2026-06-17.