First published: Sun Mar 04 2018(Updated: )
In Exponent CMS before 2.4.1 Patch #6, certain admin users can elevate their privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exponentcms Exponent Cms | <=2.4.1 | |
Exponentcms Exponent Cms | =2.4.1-p1 | |
Exponentcms Exponent Cms | =2.4.1-p2 | |
Exponentcms Exponent Cms | =2.4.1-p3 | |
Exponentcms Exponent Cms | =2.4.1-p4 | |
Exponentcms Exponent Cms | =2.4.1-p5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18213 is considered a medium severity vulnerability due to the potential privilege escalation by certain admin users.
To fix CVE-2017-18213, upgrade Exponent CMS to version 2.4.1 Patch #6 or later.
CVE-2017-18213 affects Exponent CMS versions prior to 2.4.1 Patch #6.
CVE-2017-18213 is a privilege escalation vulnerability allowing certain admin users to gain elevated permissions.
Yes, an official patch for CVE-2017-18213 was released as part of Exponent CMS version 2.4.1 Patch #6.