CVE-2017-17920 is a vulnerability in Ruby on Rails
Published on December 29, 2017
SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input
Products Associated with CVE-2017-17920
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2017-17920 are published in Ruby on Rails:
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.