High severity8.8NVD Advisory· Published Apr 11, 2017· Updated May 13, 2026
CVE-2017-7694
CVE-2017-7694
Description
Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attackers to execute code and get a webshell from the back-end. The attacker must be authenticated and enter PHP code in the datasource editor or event editor.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/symphonycms/symphony-2/commit/e30a18f8f09dca836e141bf126a26e565c9a2bc7nvdPatch
- github.com/symphonycms/symphony-2/issues/2655nvdIssue TrackingPatch
- www.math1as.com/symphonycms_2.7_exec.txtnvdExploitThird Party Advisory
- www.securityfocus.com/bid/97594nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.