CVE-2017-6480: Groovel Project Cmsgroovel
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
groovel/cmsgroovel before 3.3.7-beta is vulnerable to a reflected XSS in commons/browser.php (path parameter).
Affected products
- Groovel Project Cmsgroovel: up to and including 3.3.6
Published 2017-03-05. Last modified 2026-06-17.