CVE-2017-17972: Archon Project Archon
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
packages/subjects/pub/subjects.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?subjecttypeid=xxx request, aka Open Bug Bounty ID OBB-466362.
Affected products
- Archon Project Archon: version 3.21 only
Published 2019-07-03. Last modified 2026-06-17.