There is reflected XSS in TOPdesk before 5.7.6 and 6.x and 7.x before 7.03.019.
Conclusion & alert: CVE-2017-7276 is rated Moderate Risk (41.7/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.27%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-17 | 0.08% | 0.27% | +0.19% |
| 2 | 2023-03-07 | 0.89% | 0.08% | -0.81% |
| 3 | 2022-02-04 | — | 0.89% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.1 | 3.0 | MEDIUM |
|
2.8 | 2.7 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| topdesk | topdesk | <= 5.7.5 | cpe:2.3:a:topdesk:topdesk:*:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.04.001 | cpe:2.3:a:topdesk:topdesk:6.04.001:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.04.005 | cpe:2.3:a:topdesk:topdesk:6.04.005:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.04.006 | cpe:2.3:a:topdesk:topdesk:6.04.006:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.04.008 | cpe:2.3:a:topdesk:topdesk:6.04.008:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.04.011 | cpe:2.3:a:topdesk:topdesk:6.04.011:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.04.012 | cpe:2.3:a:topdesk:topdesk:6.04.012:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.04.013 | cpe:2.3:a:topdesk:topdesk:6.04.013:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.04.015 | cpe:2.3:a:topdesk:topdesk:6.04.015:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.04.016 | cpe:2.3:a:topdesk:topdesk:6.04.016:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.05.002 | cpe:2.3:a:topdesk:topdesk:6.05.002:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.05.006 | cpe:2.3:a:topdesk:topdesk:6.05.006:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.05.007 | cpe:2.3:a:topdesk:topdesk:6.05.007:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.05.008 | cpe:2.3:a:topdesk:topdesk:6.05.008:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.05.009 | cpe:2.3:a:topdesk:topdesk:6.05.009:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.05.010 | cpe:2.3:a:topdesk:topdesk:6.05.010:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.05.016 | cpe:2.3:a:topdesk:topdesk:6.05.016:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.05.017 | cpe:2.3:a:topdesk:topdesk:6.05.017:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.06.002 | cpe:2.3:a:topdesk:topdesk:6.06.002:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.06.003 | cpe:2.3:a:topdesk:topdesk:6.06.003:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.06.004 | cpe:2.3:a:topdesk:topdesk:6.06.004:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.06.005 | cpe:2.3:a:topdesk:topdesk:6.06.005:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.06.006 | cpe:2.3:a:topdesk:topdesk:6.06.006:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.06.007 | cpe:2.3:a:topdesk:topdesk:6.06.007:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.06.013 | cpe:2.3:a:topdesk:topdesk:6.06.013:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.06.014 | cpe:2.3:a:topdesk:topdesk:6.06.014:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.06.020 | cpe:2.3:a:topdesk:topdesk:6.06.020:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.07.002 | cpe:2.3:a:topdesk:topdesk:6.07.002:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.07.005 | cpe:2.3:a:topdesk:topdesk:6.07.005:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.07.007 | cpe:2.3:a:topdesk:topdesk:6.07.007:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.07.010 | cpe:2.3:a:topdesk:topdesk:6.07.010:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.07.014 | cpe:2.3:a:topdesk:topdesk:6.07.014:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.07.019 | cpe:2.3:a:topdesk:topdesk:6.07.019:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.07.022 | cpe:2.3:a:topdesk:topdesk:6.07.022:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.07.023 | cpe:2.3:a:topdesk:topdesk:6.07.023:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.08.001 | cpe:2.3:a:topdesk:topdesk:6.08.001:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.08.011 | cpe:2.3:a:topdesk:topdesk:6.08.011:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.08.016 | cpe:2.3:a:topdesk:topdesk:6.08.016:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.08.020 | cpe:2.3:a:topdesk:topdesk:6.08.020:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.08.021 | cpe:2.3:a:topdesk:topdesk:6.08.021:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.08.024 | cpe:2.3:a:topdesk:topdesk:6.08.024:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.08.025 | cpe:2.3:a:topdesk:topdesk:6.08.025:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.08.029 | cpe:2.3:a:topdesk:topdesk:6.08.029:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.08.030 | cpe:2.3:a:topdesk:topdesk:6.08.030:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.08.031 | cpe:2.3:a:topdesk:topdesk:6.08.031:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.08.033 | cpe:2.3:a:topdesk:topdesk:6.08.033:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.08.034 | cpe:2.3:a:topdesk:topdesk:6.08.034:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.09.001 | cpe:2.3:a:topdesk:topdesk:6.09.001:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.09.005 | cpe:2.3:a:topdesk:topdesk:6.09.005:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.09.010 | cpe:2.3:a:topdesk:topdesk:6.09.010:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.09.011 | cpe:2.3:a:topdesk:topdesk:6.09.011:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.09.012 | cpe:2.3:a:topdesk:topdesk:6.09.012:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.09.013 | cpe:2.3:a:topdesk:topdesk:6.09.013:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.09.014 | cpe:2.3:a:topdesk:topdesk:6.09.014:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.09.015 | cpe:2.3:a:topdesk:topdesk:6.09.015:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.09.017 | cpe:2.3:a:topdesk:topdesk:6.09.017:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.09.018 | cpe:2.3:a:topdesk:topdesk:6.09.018:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.09.019 | cpe:2.3:a:topdesk:topdesk:6.09.019:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.09.021 | cpe:2.3:a:topdesk:topdesk:6.09.021:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.09.022 | cpe:2.3:a:topdesk:topdesk:6.09.022:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.09.023 | cpe:2.3:a:topdesk:topdesk:6.09.023:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.09.024 | cpe:2.3:a:topdesk:topdesk:6.09.024:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.10.008 | cpe:2.3:a:topdesk:topdesk:6.10.008:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.10.015 | cpe:2.3:a:topdesk:topdesk:6.10.015:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.10.021 | cpe:2.3:a:topdesk:topdesk:6.10.021:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.10.022 | cpe:2.3:a:topdesk:topdesk:6.10.022:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.10.025 | cpe:2.3:a:topdesk:topdesk:6.10.025:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.10.026 | cpe:2.3:a:topdesk:topdesk:6.10.026:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.10.027 | cpe:2.3:a:topdesk:topdesk:6.10.027:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.10.037 | cpe:2.3:a:topdesk:topdesk:6.10.037:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.10.040 | cpe:2.3:a:topdesk:topdesk:6.10.040:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.11.003 | cpe:2.3:a:topdesk:topdesk:6.11.003:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.11.015 | cpe:2.3:a:topdesk:topdesk:6.11.015:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.11.024 | cpe:2.3:a:topdesk:topdesk:6.11.024:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.11.030 | cpe:2.3:a:topdesk:topdesk:6.11.030:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.12.006 | cpe:2.3:a:topdesk:topdesk:6.12.006:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.12.007 | cpe:2.3:a:topdesk:topdesk:6.12.007:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.12.008 | cpe:2.3:a:topdesk:topdesk:6.12.008:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.12.013 | cpe:2.3:a:topdesk:topdesk:6.12.013:*:*:*:*:*:*:* |
| topdesk | topdesk | 6.12.015 | cpe:2.3:a:topdesk:topdesk:6.12.015:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://page.topdesk.com/cve-2017-7276 | Vendor Advisory |