Back
CVE-2017-10816
CRITICAL
SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to execute arbitrary SQL commands via Relay Service Server.
Published: Aug 4, 2017
Modified: Jun 17, 2026
CWE-89
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| intercom | malion | * |
| intercom | malion | * |
GitHub Security Advisory GHSA-g2x8-xg98-q8g6
SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote...
References (4)
- http://www.intercom.co.jp/information/2017/0801.html Vendor Advisory
- https://jvn.jp/en/vu/JVNVU91587298/index.html Third Party Advisory, VDB Entry
- http://www.intercom.co.jp/information/2017/0801.html Vendor Advisory
- https://jvn.jp/en/vu/JVNVU91587298/index.html Third Party Advisory, VDB Entry
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
2.21%
Top 19% most likely to be exploited
Threat Score
39.9 / 100
Data Sources
NVD
EPSS
GitHub