CVE-2017-15367
Bacula-web SQL Injection Vulnerabilities
9.8
CRITICAL
CVSS 3.1
EPSS 24.3%
Description
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.
How to fix CVE-2017-15367
To remediate CVE-2017-15367, upgrade the affected package to a fixed version below.
- Packagist/bacula-web/bacula-web—upgrade to 8.0.0-rc2 or later
Is CVE-2017-15367 being exploited?
Moderate — EPSS is 24.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 8.0.0-rc2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |