CVE-2017-9443

Publication date

2017-06-05 19:00:00

Family

mitre

State

PUBLISHED

Description

BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded package. This issue exists in coreadminmodulesdeveloperextensionsinstallprocess.php and coreadminmodulesdeveloperpackagesinstallprocess.php. NOTE: the vendor states "You must implicitly trust any package or extension you install as they all have the ability to write PHP files.