CVE-2018-17288: Kofax Front Office Server

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Kofax Front Office Server version 4.1.1.11.0.5212 (both Thin Client and Administration Console) suffers from multiple authenticated stored XSS vulnerabilities via the (1) "Filename" field in /Kofax/KFS/ThinClient/document/upload/ - (Thin Client) or (2) "DeviceName" field in /Kofax/KFS/Admin/DeviceService/device/ - (Administration Console).

Affected products

  • Kofax Front Office Server: version 4.1.1.11.0.5212 only

Published 2019-04-18. Last modified 2026-06-17.