CVE-2017-14198
—CVSS 3.0
8.8 high
EPSS
2%p77
Published
()
Modified
Description
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause Remote Code Execution (RCE) via a maliciously crafted time_format tag.
- Vendors
- squiz
- Products
- matrix
- Weakness
- CWE-94
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.