PT-2018-9399 · Instant Update · Instant Update Cms
Publicado
2018-06-26
·
Atualizado
2018-08-30
·
CVE-2018-1000501
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Instant Update CMS versions prior to 0.3.3
Description
The issue is related to a password reset vulnerability in the /iu-application/controllers/administration/auth.php file, which can lead to account takeover. This can be exploited via network connectivity.
Recommendations
For versions prior to 0.3.3, update to version 0.3.3 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable auth.php file until the update is applied.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Instant Update Cms