CVE-2018-17173

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
21/09/2018
Last modified:
06/05/2019

Description

LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lg:supersign_cms:2.5:*:*:*:*:*:*:*