First published: Tue Mar 13 2018(Updated: )
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mentiss Acgv Acgvannu | =2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000080 is classified as a medium severity vulnerability due to its potential for misuse by normal users.
To fix CVE-2018-1000080, ensure that permissions for plugin downloads are properly configured to restrict access to authorized users only.
CVE-2018-1000080 affects users of Ajenti version 2, particularly those using the plugins feature.
CVE-2018-1000080 is categorized as an Insecure Permissions vulnerability, allowing unauthorized plugin downloads.
Yes, CVE-2018-1000080 can be exploited remotely if an attacker can craft the appropriate requests.