CVE Database
/

CVE-2017-0897

Back to search

CVE-2017-0897

Published: Jun 22, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.

VendorProductVersions

EllisLab

ExpressionEngine

affected
Versions before 2.11.8 and 3.5.5

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now