CVE-2017-20197
HIGHpropanetank Roommate-Bill-Tracking - SQL Injection in /includes/login.php
Title source: llmDescription
A vulnerability was found in propanetank Roommate-Bill-Tracking up to 288437f658fc9ee7d4b92a9da12557024d8bc55c. It has been declared as critical. This vulnerability affects unknown code of the file /includes/login.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The name of the patch is b32bb1b940f82d38fb9310cd66ebe349e20a1d0a. It is recommended to apply a patch to fix this issue.
References (3)
Core 3
Core References
Permissions Required, VDB Entry vdb-entry
technical-description
https://vuldb.com/?id.303640
Permissions Required, VDB Entry signature
permissions-required
https://vuldb.com/?ctiid.303640
Scores
CVSS v3
7.3
EPSS
0.0033
EPSS Percentile
24.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-74
CWE-89
Status
published
Products (1)
propanetank/Roommate-Bill-Tracking
288437f658fc9ee7d4b92a9da12557024d8bc55c
Published
Apr 09, 2025
Tracked Since
Feb 18, 2026