High severity8.8NVD Advisory· Published Jun 5, 2017· Updated May 13, 2026
CVE-2017-9443
CVE-2017-9443
Description
BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded package. This issue exists in core\admin\modules\developer\extensions\install\process.php and core\admin\modules\developer\packages\install\process.php. NOTE: the vendor states "You must implicitly trust any package or extension you install as they all have the ability to write PHP files.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/bigtreecms/BigTree-CMS/issues/292nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.