PT-2018-14247 · Nuuo · Nuuo Cms

Pedro Ribeiro

·

Published

2018-10-12

·

Updated

2019-10-09

·

CVE-2018-17888

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NUUO CMS versions 3.1 and prior
Description The issue concerns a session identification mechanism in the application that could allow attackers to obtain the active session ID. This could potentially lead to arbitrary remote code execution.
Recommendations For NUUO CMS versions 3.1 and prior, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17888

Affected Products

Nuuo Cms