PT-2017-10698 · Ellislab · Expressionengine
Published
2017-06-22
·
Updated
2019-10-09
·
CVE-2017-0897
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ExpressionEngine versions 2.x through 2.11.7
ExpressionEngine versions 3.x through 3.5.4
Description
The issue allows for the creation of an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.
Recommendations
For ExpressionEngine versions 2.x through 2.11.7, update to version 2.11.8 or later.
For ExpressionEngine versions 3.x through 3.5.4, update to version 3.5.5 or later.
Fix
RCE
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Expressionengine