CVE-2017-16896
CRITICALTiny Tiny RSS 17.4 - SQL Injection via Forgot Password Login Parameter
Title source: llmDescription
A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter.
References (2)
Core 2
Core References
Patch x_refsource_misc
https://git.tt-rss.org/git/tt-rss/commit/2352c320c2ed34ec7df1ad22f0c55a1b26489815
Patch, Vendor Advisory x_refsource_misc
https://discourse.tt-rss.org/t/sql-injection-in-forgotpass-fixed/669
Scores
CVSS v3
9.8
EPSS
0.0148
EPSS Percentile
71.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
tt-rss/tiny_tiny_rss
17.4
Published
Nov 20, 2017
Tracked Since
Feb 18, 2026