CVE-2017-20178

LOW

Codiad < 2.8.1 - Information Disclosure via saveJSON Function

Title source: llm
STIX 2.1

Description

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function saveJSON of the file components/install/process.php. The manipulation of the argument data leads to information disclosure. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 2.8.1 is able to address this issue. The patch is identified as 517119de673e62547ee472a730be0604f44342b5. It is recommended to upgrade the affected component. VDB-221498 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

References (5)

Core 5
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.221498
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.221498
Issue Tracking, Patch issue-tracking
https://github.com/Codiad/Codiad/pull/974

Scores

CVSS v3 3.1
EPSS 0.0068
EPSS Percentile 47.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
codiad/codiad 2.8.0
codiad/codiad 0 - 2.8.1Packagist
Published Feb 21, 2023
Tracked Since Feb 18, 2026