{"id":"CVE-2017-6484","aliases":["GHSA-w969-pq6x-267j"],"url":"https://o3.security/vulnerability/CVE-2017-6484","summary":"INTER-Mediator Cross-Site Scripting (XSS)","details":"Multiple Cross-Site Scripting (XSS) issues were discovered in INTER-Mediator 5.5. The vulnerabilities exist due to insufficient filtration of user-supplied data (c and cred) passed to the \"INTER-Mediator-master/Auth_Support/PasswordReset/resetpassword.php\" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.","published":"2017-03-05T20:59:00.387Z","modified":"2026-07-08T12:28:28.883540Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"inter-mediator/inter-mediator","fixedVersion":"5.6"}],"fix":null,"references":[{"type":"EVIDENCE","url":"https://github.com/INTER-Mediator/INTER-Mediator/issues/772"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:28:28.883540Z"}}