CVE-2017-14653: ASP4CMS Aspcms
Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.
member/Orderinfo.asp in ASP4CMS AspCMS 2.7.2 allows remote authenticated users to read arbitrary order information via a modified OrderNo parameter.
Affected products
- ASP4CMS Aspcms: version 2.7.2 only
Published 2017-09-22. Last modified 2026-06-17.