PT-2018-12604 · Wancms · Wancms

Publicado

2018-07-25

·

Atualizado

2019-10-03

·

CVE-2018-14596

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions wancms versions 1.0 through 5.0
Description The issue allows remote attackers to cause a denial of service, specifically resource consumption, by manipulating the checkcode URI with large values for font size, width, and height parameters.
Recommendations For wancms versions 1.0 through 5.0, consider restricting access to the checkcode URI or limiting the values that can be assigned to font size, width, and height parameters to prevent excessive resource consumption. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-14596

Produtos afetados

Wancms