SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via the tags array parameter.
{ "extracted_events": [ { "introduced": "4.2.18" }, { "last_affected": "4.2.18" } ], "cpe": "cpe:2.3:a:bigtreecms:bigtree_cms:4.2.18:*:*:*:*:*:*:*", "source": "CPE_STRING" }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-11736.json"