CVE-2017-1000235: Scilico I, Librarian

Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.

I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised.

Affected products

  • Scilico I, Librarian: up to and including 4.6; version 4.7 only

Published 2017-11-17. Last modified 2026-06-17.