CVE-2017-7997: Gespage
Critical severity, CVSS 9.8. EPSS: 19.3% chance of exploitation in the next 30 days.
Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands via the (1) show_prn parameter to webapp/users/prnow.jsp or show_month parameter to (2) webapp/users/blhistory.jsp or (3) webapp/users/prhistory.jsp.
Affected products
- Gespage Gespage: before 7.4.9 (fixed in 7.4.9)
Published 2018-01-08. Last modified 2026-06-17.