{"id":"CVE-2017-8384","aliases":["GHSA-9mcw-mwxv-grwj"],"url":"https://o3.security/vulnerability/CVE-2017-8384","summary":"Craft CMS XSS Vulnerability","details":"Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.","published":"2017-05-01T06:59:00.250Z","modified":"2026-08-07T14:53:46.596299Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"2.6.2976"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://craftcms.com/changelog#2-6-2976"},{"type":"ADVISORY","url":"https://twitter.com/CraftCMS/status/857743080224473088"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:53:46.596299Z"}}