PT-2018-14247 · Nuuo · Nuuo Cms

Pedro Ribeiro

·

Publicado

2018-10-12

·

Atualizado

2019-10-09

·

CVE-2018-17888

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NUUO CMS versions 3.1 and prior
Description The issue concerns a session identification mechanism in the application that could allow attackers to obtain the active session ID. This could potentially lead to arbitrary remote code execution.
Recommendations For NUUO CMS versions 3.1 and prior, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Insufficiently Random Values

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-17888

Produtos afetados

Nuuo Cms