CVE-2017-2124: Onethird CMS

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

Cross-site scripting vulnerability in OneThird CMS v1.73 Heaven's Door and earlier allows remote attackers to inject arbitrary web script or HTML via contact.php.

Affected products

  • Onethird Onethird CMS: up to and including 1.7.3

Published 2017-04-28. Last modified 2026-06-17.