CVE-2017-17730: SQL Injection
Published Dec 18, 2017
·Updated
DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flinkadd.php.
Affected Software
1 affected component
DedeCMS Dedecms<=5.7
Event History
Dec 18, 2017
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17730?
CVE-2017-17730 has a medium severity level, impacting the security of affected systems.
2
How do I fix CVE-2017-17730?
To fix CVE-2017-17730, update to a version of DedeCMS that is above 5.7 where this vulnerability is resolved.
3
What type of vulnerability is CVE-2017-17730?
CVE-2017-17730 is classified as an SQL Injection vulnerability.
4
What parameters are affected by CVE-2017-17730?
CVE-2017-17730 specifically affects the 'logo' parameter in plus/flink_add.php.
5
Which versions of DedeCMS are vulnerable to CVE-2017-17730?
DedeCMS versions up to and including 5.7 are vulnerable to CVE-2017-17730.