Back to Database
Status published
Medium
CVE-2017-20018
XAMPP Installer uncontrolled search path
Vulnerability Description
A vulnerability was found in XAMPP 7.1.1-0-VC14. It has been classified as problematic. Affected is an unknown function of the component Installer. The manipulation leads to privilege escalation. It is possible to launch the attack remotely.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-20018
Credits & Attribution
No credits recorded in the NVD database.
References
More from unspecified
View All →CVE-2022-4642
tatoeba2 Profile Name cross site scripting
Low
3.5
CVE-2022-4641
pig-vector LogisticRegression.java LogisticRegression temp file
Low
2.5
CVE-2022-4639
sslh Packet Dumping probe.c hexdump format string
Medium
5.6
CVE-2022-4638
collective.contact.widget widgets.py title cross site scripting
Low
3.5
CVE-2022-4631
WP-Ban ban-options.php cross site scripting
Low
3.5
Affected Vendor
unspecified
View all reports →Affected Software
XAMPP
Vulnerable Versions:
7.1.1-0-VC14
Timeline
Official Publish:
June 9th, 2022
Last Modified:
April 15th, 2025
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L