A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database. The attack uses an admin/trees/add/process request with a crafted _tags[] parameter that is mishandled in a later admin/ajax/dashboard/approve-change request.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/bigtreecms/BigTree-CMS/issues/323 |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T20:43:57.827Z
Reserved: 2017-11-27T00:00:00
Link: CVE-2017-16961

No data.

Status : Deferred
Published: 2017-11-27T10:29:00.597
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-16961

No data.