SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or id parameters to topics/deletetopics.php; the (2) id parameter to bookmarks/deletebookmarks.php; or the (3) id parameter to calendar/deletecalendar.php.
CVE-2017-6089
Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2022-05-17. NVD baseline CVSS 9.8; sources differ by 0.0.
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.8
- EG Score
- 9.8(medium)
- EG Risk
- 65(Track*)EG Risk 65/100SSVC: Track*
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity98% × 45%Exploitation40% × 40%Automatability30% × 15%Action: Watch closely — could escalate to Attend. - EPSS PROB
- 3%
- EPSS %ILE
- 86%
- KEV
- Not listed
Published
October 3, 2017
Last Modified
June 17, 2026
Advisory Details (2)
Auto-updated Sep 7, 2026phpCollab 2.5.1 - SQL Injection - PHP webapps Exploit
https://www.exploit-db.com/exploits/42935/[CVE-2017-6089] PhpCollab 2.5.1 Multiple SQL Injections (unauthenticated) - Audit et formations en sécurité informatique
https://sysdream.com/news/lab/2017-09-29-cve-2017-6089-phpcollab-2-5-1-multiple-sql-injections-unauthenticated/Publicly available exploits
(1 reference)Working exploit code is in the public domain (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- Exploit-DBEDB-42935First seen Oct 2, 2017
phpCollab 2.5.1 - SQL Injection
Open source ↗
Frequently asked(5)
What is CVE-2017-6089?
When was CVE-2017-6089 disclosed?
Is CVE-2017-6089 actively exploited?
What is the CVSS score of CVE-2017-6089?
How do I remediate CVE-2017-6089?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2017-6089
Is Your Infrastructure Affected by CVE-2017-6089?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.