PT-2017-10698 · Ellislab · Expressionengine

Published

2017-06-22

·

Updated

2019-10-09

·

CVE-2017-0897

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ExpressionEngine versions 2.x through 2.11.7 ExpressionEngine versions 3.x through 3.5.4
Description The issue allows for the creation of an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.
Recommendations For ExpressionEngine versions 2.x through 2.11.7, update to version 2.11.8 or later. For ExpressionEngine versions 3.x through 3.5.4, update to version 3.5.5 or later.

Fix

RCE

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-0897

Affected Products

Expressionengine