CVE-2017-9443

** DISPUTED ** BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded package. This issue exists in coreadminmodulesdeveloperextensionsinstallprocess.php and coreadminmodulesdeveloperpackagesinstallprocess.php. NOTE: the vendor states "You must implicitly trust any package or extension you install as they all have the ability to write PHP files."

Date published : 2017-06-05

https://github.com/bigtreecms/BigTree-CMS/issues/292