CVE-2017-20018: XAMPP Installer uncontrolled search path
Published Jun 9, 2022
·Updated
A vulnerability was found in XAMPP 7.1.1-0-VC14. It has been classified as problematic. Affected is an unknown function of the component Installer. The manipulation leads to privilege escalation. It is possible to launch the attack remotely.
Affected Software
1 affected component
Apachefriends Xampp=7.1.1-0-vc14
Event History
Jun 9, 2022
CVE Published
via MITRE·10:35 PM
Data Sourced
via MITRE·10:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-20018?
The severity of CVE-2017-20018 is high with a severity value of 7.8.
2
What is the affected software of CVE-2017-20018?
The affected software of CVE-2017-20018 is XAMPP version 7.1.1-0-VC14.
3
How can the vulnerability in CVE-2017-20018 be exploited?
The vulnerability in CVE-2017-20018 can be exploited by manipulating an unknown function in the XAMPP Installer component, allowing for privilege escalation attacks.
4
Is CVE-2017-20018 a remote vulnerability?
Yes, CVE-2017-20018 is a remote vulnerability, meaning the attack can be launched remotely.
5
Is there a fix available for CVE-2017-20018?
Yes, it is recommended to update to a secure version of XAMPP that does not have this vulnerability.