{"id":"CVE-2017-15367","aliases":["GHSA-fv4m-5j2c-787r"],"url":"https://o3.security/vulnerability/CVE-2017-15367","summary":"Bacula-web SQL Injection Vulnerabilities","details":"Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.","published":"2018-03-07T20:29:00.247Z","modified":"2026-07-08T05:50:23.621652199Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Packagist","name":"bacula-web/bacula-web","fixedVersion":"8.0.0-rc2"}],"fix":{"url":"https://github.com/bacula-web/bacula-web/commit/90d4c44a0dd0d65c6fb3ab2417b83d700c8413ae","label":"bacula-web/bacula-web@90d4c44"},"references":[{"type":"ADVISORY","url":"http://bacula-web.org/download/articles/bacula-web-8-0-0-rc2.html"},{"type":"REPORT","url":"http://bugs.bacula-web.org/view.php?id=211"},{"type":"FIX","url":"https://github.com/bacula-web/bacula-web/commit/90d4c44a0dd0d65c6fb3ab2417b83d700c8413ae"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/44272/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:50:23.621652199Z"}}