Lucene search

K
cvelistVulDBCVELIST:CVE-2017-20052
HistoryJun 16, 2022 - 6:15 a.m.

CVE-2017-20052 Python pgAdmin4 uncontrolled search path

2022-06-1606:15:20
CWE-427
VulDB
www.cve.org

5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

0.001 Low

EPSS

Percentile

33.0%

A vulnerability classified as problematic was found in Python 2.7.13. This vulnerability affects unknown code of the component pgAdmin4. The manipulation leads to uncontrolled search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CNA Affected

[
  {
    "product": "Python",
    "vendor": "unspecified",
    "versions": [
      {
        "status": "affected",
        "version": "2.7.13"
      }
    ]
  }
]

5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

0.001 Low

EPSS

Percentile

33.0%

Related for CVELIST:CVE-2017-20052