PT-2018-14963 · Ucms · Ucms

Published

2018-11-22

·

Updated

2019-10-03

·

CVE-2018-19437

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UCMS version 1.4.7
Description The issue allows remote authenticated users to change the administrator password. This is possible because the software uses the value of $ COOKIE['admin '.cookiehash] for arbitrary cookie values that are set and not empty.
Recommendations For UCMS version 1.4.7, consider restricting access to the administrator password change functionality until a proper fix is applied, and ensure that cookie values are properly validated to prevent unauthorized changes.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-19437

Affected Products

Ucms