CVE-2017-20051

MEDIUM

InnoSetup Installer - Path Traversal

Title source: llm

Description

A vulnerability was found in InnoSetup Installer. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to uncontrolled search path. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Scores

CVSS v3 6.3
EPSS 0.0022
EPSS Percentile 44.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-427
Status published

Affected Products (1)

jrsoftware/inno_setup

Timeline

Published Jun 16, 2022
Tracked Since Feb 18, 2026