CVE-2017-14653: ASP4CMS Aspcms

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

member/Orderinfo.asp in ASP4CMS AspCMS 2.7.2 allows remote authenticated users to read arbitrary order information via a modified OrderNo parameter.

Affected products

Published 2017-09-22. Last modified 2026-06-17.