← Vulnerability feed

Vulnerability record · CVE-2017-14620 · published 30 September 2017

CVE-2017-14620: Smartertools smarterstats cross-site scripting vulnerability

Smartertools · Smarterstats

SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Stored Cross Site Scripting.

6.1 CVSS 3.0 Medium EPSS 2.5% · top 16.1% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
2.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Stored Cross Site Scripting.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://xss.cx/cve/2017/14620/smarterstats.v11-3-6347.html ExploitThird Party Advisory
https://www.exploit-db.com/exploits/42923/ ExploitThird Party AdvisoryVDB Entry
http://xss.cx/cve/2017/14620/smarterstats.v11-3-6347.html ExploitThird Party Advisory
https://www.exploit-db.com/exploits/42923/ ExploitThird Party AdvisoryVDB Entry

Track CVE-2017-14620 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-4752Smartertools smarterstats vulnerabilitySmarterTools SmarterStats 6.2.4100 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecif…EPSS 1.8%10.0CVE-2011-2148Smartertools smarterstats os command injection vulnerabilityAdmin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands via vectors involving a lead…EPSS 5.3%10.0CVE-2011-2158Smartertools smarterstats vulnerabilityThe SmarterTools SmarterStats 6.0 web server sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have a…EPSS 4.4%10.0CVE-2011-2159Smartertools smarterstats vulnerabilityThe SmarterTools SmarterStats 6.0 web server omits the Content-Type header for certain resources, which might allow remote attackers to have an unspe…EPSS 4.4%7.5CVE-2011-2149Smartertools smarterstats sql injection vulnerabilityMultiple SQL injection vulnerabilities in the SmarterTools SmarterStats 6.0 web server allow remote attackers to execute arbitrary SQL commands via c…EPSS 2.4%7.5CVE-2011-2155Smartertools smarterstats improper authentication vulnerabilityLogin.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocomplete f…EPSS 3.9%5.0CVE-2011-4751Smartertools smarterstats information exposure vulnerabilitySmarterTools SmarterStats 6.2.4100 generates web pages containing external links in response to GET requests with query strings for frmGettingStarted…EPSS 1.1%5.0CVE-2011-2150Smartertools smarterstats improper input validation vulnerabilityThe SmarterTools SmarterStats 6.0 web server does not properly validate string data that is intended for storage in an XML document, which allows rem…EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2017-14620), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.