CVE-2017-16962
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 2.2%
from disclosure to weapon0 days
Published on NVDNov 27
1st PoCNov 15
exploitation probability
2.2%top 19% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities via (1) the location or details field of a Google Calendar invitation, (2) a crafted Outlook.com calendar (aka Hotmail Calendar) invitation, (3) e-mail granting access to a directory that has JavaScript in its name, (4) JavaScript in a note name, (5) JavaScript in a task name, or (6) HTML e-mail that is mishandled in the Inbox component.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/145095/communigatepro-xss.txtunverifiedcve_referencewww.exploit-db.com/exploits/43177/unverifiedexploitdbwww.exploit-db.com/exploits/43177unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.