Vulnerability record · CVE-2017-20178 · published 21 February 2023
CVE-2017-20178: Codiad information exposure vulnerability
CCodiad · Codiad
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function saveJSON of the file components/install/process.php. The manipulation of the argument data leads to information disclosure. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 2.8.1 is able to address this issue. The patch is identified as 517119de673e62547ee472a730be0604f44342b5. It is recommended to upgrade the affected component. VDB-221498 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Description
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function saveJSON of the file components/install/process.php. The manipulation of the argument data leads to information disclosure. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 2.8.1 is able to address this issue. The patch is identified as 517119de673e62547ee472a730be0604f44342b5. It is recommended to upgrade the affected component. VDB-221498 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/Codiad/Codiad/commit/517119de673e62547ee472a730be0604f44342b5 | Patch |
| https://github.com/Codiad/Codiad/pull/974 | Issue TrackingPatch |
| https://github.com/Codiad/Codiad/releases/tag/v.2.8.1 | Release Notes |
| https://vuldb.com/?ctiid.221498 | Permissions RequiredThird Party Advisory |
| https://vuldb.com/?id.221498 | Third Party Advisory |
| https://github.com/Codiad/Codiad/commit/517119de673e62547ee472a730be0604f44342b5 | Patch |
| https://github.com/Codiad/Codiad/pull/974 | Issue TrackingPatch |
| https://github.com/Codiad/Codiad/releases/tag/v.2.8.1 | Release Notes |
| https://vuldb.com/?ctiid.221498 | Permissions RequiredThird Party Advisory |
| https://vuldb.com/?id.221498 | Third Party Advisory |
Track CVE-2017-20178 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-20178), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.