CVE-2017-20173
MEDIUMcontentmap < 2017-03-08 - SQL Injection via contentid Argument in Load Function
Title source: llmDescription
A vulnerability was found in AlexRed contentmap. It has been rated as critical. Affected by this issue is the function Load of the file contentmap.php. The manipulation of the argument contentid leads to sql injection. The name of the patch is dd265d23ff4abac97422835002c6a47f45ae2a66. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218492.
References (3)
Core 3
Core References
Third Party Advisory vdb-entry
technical-description
https://vuldb.com/?id.218492
Permissions Required, Third Party Advisory signature
permissions-required
https://vuldb.com/?ctiid.218492
Patch, Third Party Advisory patch
https://github.com/AlexRed/contentmap/commit/dd265d23ff4abac97422835002c6a47f45ae2a66
Scores
CVSS v3
5.5
EPSS
0.0061
EPSS Percentile
45.7%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-89
Status
published
Products (1)
contentmap_project/contentmap
< 2017-03-08
Published
Jan 18, 2023
Tracked Since
Feb 18, 2026