{"id":"CVE-2017-7694","details":"Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attackers to execute code and get a webshell from the back-end. The attacker must be authenticated and enter PHP code in the datasource editor or event editor.","modified":"2026-07-08T16:53:44.871034Z","published":"2017-04-11T23:59:00.203Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/97594"},{"type":"FIX","url":"https://github.com/symphonycms/symphony-2/commit/e30a18f8f09dca836e141bf126a26e565c9a2bc7"},{"type":"FIX","url":"https://github.com/symphonycms/symphony-2/issues/2655"},{"type":"EVIDENCE","url":"http://www.math1as.com/symphonycms_2.7_exec.txt"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/symphonycms/symphonycms","events":[{"introduced":"0"},{"last_affected":"dba6406087cb72e824b3f01d710cd52da3afaa26"},{"fixed":"e30a18f8f09dca836e141bf126a26e565c9a2bc7"}],"database_specific":{"cpe":"cpe:2.3:a:getsymphony:symphony:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.6.11"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["2.6.11","2.6.10","2.6.9","2.6.8","2.6.7","2.6.6","2.6.4","2.6.5","2.6.3","2.6.2","2.6.1","2.6.0","2.6.0-rc.1","2.5.2","2.6.0-beta.2","2.6.0-beta.1","2.5.2-rc.1","2.5.2-beta.1","2.5.1","2.5.0","2.4","2.4RC2","2.4RC1","2.4beta3","2.4beta1","2.3.6","2.3.5","2.3.5RC1","2.3.5beta1","2.3.4","2.3.4RC1","2.3.4beta2","2.3.3","2.3.4beta1","2.3.3RC3","2.3.3RC2","2.3.3RC1","2.3.3beta3","2.3.3beta2","2.3.3beta1","2.3.2","2.3.2RC2","2.2.5","2.3.2RC1","2.3.2beta2","2.3.2beta1","2.3.1","2.3.1RC3","2.3","2.3.1RC2","2.3.1RC1","2.3.1beta2","2.3.1beta1","2.3RC4","2.3RC3","2.3RC2","2.3beta3","2.3beta2","2.3beta1","2.2.4","2.2.3","2.2.2","2.1.2","2.2","2.0.7","2.0.7RC2","2.0.7beta","2.0.7RC1","2.0.4","2.0.2","2.0.1","2.0","rev5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7694.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}