← Back

CVE-2017-16903

nvd nist
Published: Nov 20, 2017Modified: May 13, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

LvyeCMS through 3.1 allows remote attackers to upload and execute arbitrary PHP code via directory traversal sequences in the dir parameter, in conjunction with PHP code in the content parameter, within a template Style add request to index.php.

Affected (1)

Lvyecms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.1

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.