PT-2018-11280 · Episerver · Episerver Ektron Cms

Alex Hernandez

+1

·

Published

2018-10-10

·

Updated

2019-10-03

·

CVE-2018-12596

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Episerver Ektron CMS versions prior to 9.0 SP3 Site CU 31 Episerver Ektron CMS versions 9.1 prior to SP3 Site CU 45 Episerver Ektron CMS versions 9.2 prior to SP2 Site CU 22
Description The issue allows remote attackers to call aspx pages via the "activateuser.aspx" page, even if a page is located under the /WorkArea/ path, which is normally available exclusively for local admins.
Recommendations For Episerver Ektron CMS versions prior to 9.0 SP3 Site CU 31, update to version 9.0 SP3 Site CU 31 or later. For Episerver Ektron CMS versions 9.1 prior to SP3 Site CU 45, update to version 9.1 SP3 Site CU 45 or later. For Episerver Ektron CMS versions 9.2 prior to SP2 Site CU 22, update to version 9.2 SP2 Site CU 22 or later.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12596

Affected Products

Episerver Ektron Cms