PT-2018-11280 · Episerver · Episerver Ektron Cms
Alex Hernandez
+1
·
Published
2018-10-10
·
Updated
2019-10-03
·
CVE-2018-12596
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Episerver Ektron CMS versions prior to 9.0 SP3 Site CU 31
Episerver Ektron CMS versions 9.1 prior to SP3 Site CU 45
Episerver Ektron CMS versions 9.2 prior to SP2 Site CU 22
Description
The issue allows remote attackers to call aspx pages via the "activateuser.aspx" page, even if a page is located under the /WorkArea/ path, which is normally available exclusively for local admins.
Recommendations
For Episerver Ektron CMS versions prior to 9.0 SP3 Site CU 31, update to version 9.0 SP3 Site CU 31 or later.
For Episerver Ektron CMS versions 9.1 prior to SP3 Site CU 45, update to version 9.1 SP3 Site CU 45 or later.
For Episerver Ektron CMS versions 9.2 prior to SP2 Site CU 22, update to version 9.2 SP2 Site CU 22 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Episerver Ektron Cms