CVE-2017-17976: Malicious File Upload
Published Jan 26, 2018
·Updated
In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.
Affected Software
1 affected component
Perfexcrm Perfex Crm=1.9.7
Event History
Jan 26, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-17976.
2
What is the severity of CVE-2017-17976?
The severity of CVE-2017-17976 is critical with a CVSS score of 9.8.
3
How can the vulnerability CVE-2017-17976 be exploited?
The vulnerability CVE-2017-17976 can be exploited through unrestricted file upload, which can lead to remote code execution.
4
Which version of Perfex CRM is affected by CVE-2017-17976?
Perfex CRM version 1.9.7 is affected by CVE-2017-17976.
5
How can I fix the vulnerability CVE-2017-17976 in Perfex CRM?
To fix the vulnerability CVE-2017-17976 in Perfex CRM, it is recommended to update to a patched version provided by the vendor.