CVE-2018-12596
critical · 9.8Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages via the "activateuser.aspx" page, even if a page is located under the /WorkArea/ path, which is forbidden (normally available exclusively for local admins).
9.8
CVSS
22.4%
EPSS (exploit prob.)
98th
EPSS percentile
2018-10-10
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-269
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| episerver | ektron_cms | 9.00 |
| episerver | ektron_cms | 9.00 |
| episerver | ektron_cms | 9.00 |
| episerver | ektron_cms | 9.10 |
| episerver | ektron_cms | 9.10 |
| episerver | ektron_cms | 9.10 |
| episerver | ektron_cms | 9.20 |
| episerver | ektron_cms | 9.20 |
Check a specific version with /api/v1/cve/match.
References
- http://seclists.org/fulldisclosure/2018/Oct/15
- https://github.com/alt3kx/CVE-2018-12596
- https://medium.com/%40alt3kx/ektron-content-management-system-cms-9-20-sp2-remote-re-enabling-users-cve-2018-12596-bdf1e3a05158
- https://www.exploit-db.com/exploits/45577/
- http://seclists.org/fulldisclosure/2018/Oct/15
- https://github.com/alt3kx/CVE-2018-12596
- https://medium.com/%40alt3kx/ektron-content-management-system-cms-9-20-sp2-remote-re-enabling-users-cve-2018-12596-bdf1e3a05158
- https://www.exploit-db.com/exploits/45577/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-12596