CVE-2017-20173

A vulnerability was found in AlexRed contentmap. It has been rated as critical. Affected by this issue is the function Load of the file contentmap.php. The manipulation of the argument contentid leads to sql injection. The name of the patch is dd265d23ff4abac97422835002c6a47f45ae2a66. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218492.
References
Link Resource
https://github.com/AlexRed/contentmap/commit/dd265d23ff4abac97422835002c6a47f45ae2a66 Patch Third Party Advisory
https://vuldb.com/?ctiid.218492 Permissions Required Third Party Advisory
https://vuldb.com/?id.218492 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:contentmap_project:contentmap:*:*:*:*:*:*:*:*

History

11 Apr 2024, 00:58

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en AlexRed contentmap de GitHub. Ha sido calificada como crítica. La función Load del archivo contentmap.php es afectada por esta vulnerabilidad. La manipulación del argumento contentid conduce a la inyección de SQL. El nombre del parche es dd265d23ff4abac97422835002c6a47f45ae2a66. Se recomienda aplicar un parche para solucionar este problema. El identificador de esta vulnerabilidad es VDB-218492.

Information

Published : 2023-01-18 16:15

Updated : 2024-05-17 01:17


NVD link : CVE-2017-20173

Mitre link : CVE-2017-20173

CVE.ORG link : CVE-2017-20173


JSON object : View

Products Affected

contentmap_project

  • contentmap
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')