PT-2018-12772 · Rincewind · Rincewind

Published

2018-08-03

·

Updated

2018-10-03

·

CVE-2018-14872

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Rincewind version 0.1
Description A reinstall issue exists due to the parameter p in index.php and commonPages.php, allowing an attacker to reinstall the product and reset all data.
Recommendations For Rincewind version 0.1, avoid using the parameter p in the affected files until the issue is resolved. Consider restricting access to index.php and commonPages.php to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14872

Affected Products

Rincewind