← Vulnerability feed

Vulnerability record · CVE-2017-3105 · published 1 December 2017

CVE-2017-3105: Adobe robohelp open redirect vulnerability

Adobe · Robohelp

Adobe RoboHelp has an Open Redirect vulnerability. This affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2.

6.1 CVSS 3.0 Medium EPSS 2.9% · top 13.7% CWE-601 · Open redirect
6.1CVSS 3.0 base score, v2 5.8
2.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Adobe RoboHelp has an Open Redirect vulnerability. This affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/100709 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039319 Third Party AdvisoryVDB Entry
https://helpx.adobe.com/security/products/robohelp/apsb17-25.html Issue TrackingVendor Advisory
http://www.securityfocus.com/bid/100709 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039319 Third Party AdvisoryVDB Entry
https://helpx.adobe.com/security/products/robohelp/apsb17-25.html Issue TrackingVendor Advisory

Track CVE-2017-3105 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-5327Adobe robohelp memory buffer overflow vulnerabilityMDBMS.dll in Adobe RoboHelp 10 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.EPSS 3.8%7.5CVE-2016-1035Adobe robohelp information exposure vulnerabilityAdobe RoboHelp Server 9 before 9.0.1 mishandles SQL queries, which allows attackers to obtain sensitive information via unspecified vectors.EPSS 3.5%6.5CVE-2021-21070Adobe robohelp uncontrolled search path element vulnerabilityAdobe Robohelp version 2020.0.3 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalatio…EPSS 1.6%6.1CVE-2022-23201Adobe robohelp cross-site scripting vulnerabilityAdobe RoboHelp versions 2020.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convinc…EPSS 0.68%6.1CVE-2017-3104Adobe robohelp cross-site scripting vulnerabilityAdobe RoboHelp has a cross-site scripting (XSS) vulnerability. This affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2.EPSS 2.8%6.1CVE-2016-7891Adobe robohelp cross-site scripting vulnerabilityAdobe RoboHelp version 2015.0.3 and earlier, RoboHelp 11 and earlier have an input validation issue that could be used in cross-site scripting attack…EPSS 3.2%6.1CVE-2008-0642Adobe robohelp cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in files created by Adobe RoboHelp 6 and 7, possibly involving use of a (1) WebHelp5 (WebHelp5Ext) or (2) Wi…EPSS 1.3%4.3CVE-2012-0765Adobe robohelp cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 8 and 9 for Word allow remote attackers to inject arbitrary web script or HTML …EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2017-3105), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.