CVE-2017-17999: SQL Injection
Published Jan 23, 2018
·Updated
SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to index.php/knowledgebase/getarticlesuggestion/.
Affected Software
1 affected component
FairSketch Rise Ultimate Project Manager=1.9
Event History
Jan 23, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17999?
CVE-2017-17999 is classified as a critical SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2017-17999?
To fix CVE-2017-17999, ensure that you validate and sanitize user input related to the search parameter in index.php.
3
Which software is affected by CVE-2017-17999?
CVE-2017-17999 affects RISE Ultimate Project Manager version 1.9.
4
Can CVE-2017-17999 be exploited remotely?
Yes, CVE-2017-17999 can be exploited remotely through the vulnerable search parameter.
5
What type of attack can be executed via CVE-2017-17999?
CVE-2017-17999 allows attackers to perform SQL injection attacks, which can lead to unauthorized data access or manipulation.