← back
CVE-2017-0897

CVE-2017-0897

EPSS 4.0%CWE-330
ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →