First published: Mon Dec 18 2017(Updated: )
DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms v6 | <=5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17730 has a medium severity level, impacting the security of affected systems.
To fix CVE-2017-17730, update to a version of DedeCMS that is above 5.7 where this vulnerability is resolved.
CVE-2017-17730 is classified as an SQL Injection vulnerability.
CVE-2017-17730 specifically affects the 'logo' parameter in plus/flink_add.php.
DedeCMS versions up to and including 5.7 are vulnerable to CVE-2017-17730.