CVE-2017-20051

MEDIUM

InnoSetup Installer - Path Traversal

Title source: llm
STIX 2.1

Description

A vulnerability was found in InnoSetup Installer. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to uncontrolled search path. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

References (2)

Core 2
Core References
Exploit, Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/fulldisclosure/2017/Mar/8
Third Party Advisory x_refsource_misc
https://vuldb.com/?id.97837

Scores

CVSS v3 6.3
EPSS 0.0053
EPSS Percentile 40.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-427
Status published
Products (1)
jrsoftware/inno_setup
Published Jun 16, 2022
Tracked Since Feb 18, 2026