S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 10, 2024

CVE-2017-11629 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in FineCMS affects v. through 5.0.10.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-11629
6.1
CVSS

dayrui FineCms through 5.0.10 has Cross Site Scripting (XSS) in controllers/api.php via the function parameter in a c=api&m=data2 request.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

FineCMS is a content management system (CMS) designed for building websites and web applications. It is known for its ease of use, flexibility, and compatibility with a wide variety of web development technologies. With a growing number of businesses and individuals relying heavily on online platforms, FineCMS offers an ideal solution for creating, managing, and deploying web content and applications.

However, as with any software product, FineCMS is not without vulnerabilities. One such vulnerability is CVE-2017-11629, which is associated with Cross Site Scripting (XSS) attacks. This vulnerability can be exploited through controllers/api.php via the function parameter in a c=api&m=data2 request. Essentially, this means that an attacker can inject malicious code into a web page or application, ultimately compromising the security of the system and posing a significant threat to the confidentiality, integrity, and availability of sensitive information.

If exploited, the CVE-2017-11629 vulnerability can lead to several negative consequences for both individuals and businesses. For instance, malicious actors can gain unauthorized access to databases, steal sensitive information such as credit card data and customer personal information, and take advantage of system resources through malware infection. Furthermore, the reputation of the organization can be damaged due to data breaches and other cyber attacks, leading to financial losses and loss of customer trust.

In conclusion, FineCMS is a popular CMS that makes web content management and deployment easier. However, vulnerabilities such as CVE-2017-11629 can be a serious threat to the security of the system. To protect against such vulnerabilities, it is essential to take proper precautions such as those listed above. By leveraging the pro features offered by s4e.io, readers can easily and quickly gain insight into vulnerabilities in their digital assets and take steps to mitigate the risks.

 

REFERENCES

Solution Advice

Luckily, there are many precautions that can be taken to protect against this vulnerability. These include, but are not limited to: 

  • Keeping FineCMS and all associated software and plugins up-to-date
  • Regularly scanning for vulnerabilities and malware using security tools such as those offered by securityforeveryone.com
  • Implementing proper access controls, such as two-factor authentication and role-based access
  • Configuring web application firewalls (WAFs) to monitor and block malicious traffic
  • Utilizing secure coding practices and implementing secure coding guidelines that adhere to industry standards.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-11629 scanner - Cross-Site Scripting (XSS) vulnerability in FineCMS | S4E