CVE-2017-20157: Ariadne-CMS Ariadne Component Library

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability was found in Ariadne Component Library up to 2.x. It has been classified as critical. Affected is an unknown function of the file src/url/Url.php. The manipulation leads to server-side request forgery. Upgrading to version 3.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217140.

Affected products

  • Ariadne-CMS Ariadne Component Library: before 3.0 (fixed in 3.0)

Published 2022-12-31. Last modified 2026-06-17.