CVE-2017-20178
LOWCodiad < 2.8.1 - Information Disclosure via saveJSON Function
Title source: llmDescription
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function saveJSON of the file components/install/process.php. The manipulation of the argument data leads to information disclosure. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 2.8.1 is able to address this issue. The patch is identified as 517119de673e62547ee472a730be0604f44342b5. It is recommended to upgrade the affected component. VDB-221498 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
References (5)
Core 5
Core References
Third Party Advisory vdb-entry
technical-description
https://vuldb.com/?id.221498
Permissions Required, Third Party Advisory signature
permissions-required
https://vuldb.com/?ctiid.221498
Issue Tracking, Patch issue-tracking
https://github.com/Codiad/Codiad/pull/974
Release Notes patch
https://github.com/Codiad/Codiad/releases/tag/v.2.8.1
Scores
CVSS v3
3.1
EPSS
0.0068
EPSS Percentile
47.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (2)
codiad/codiad
2.8.0
codiad/codiad
0 - 2.8.1Packagist
Published
Feb 21, 2023
Tracked Since
Feb 18, 2026