CVE-2018-1000080: Medium severity mentiss acgv acgvannu vulnerability
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000080?
CVE-2018-1000080 is classified as a medium severity vulnerability due to its potential for misuse by normal users.
How do I fix CVE-2018-1000080?
To fix CVE-2018-1000080, ensure that permissions for plugin downloads are properly configured to restrict access to authorized users only.
Who is affected by CVE-2018-1000080?
CVE-2018-1000080 affects users of Ajenti version 2, particularly those using the plugins feature.
What type of vulnerability is CVE-2018-1000080?
CVE-2018-1000080 is categorized as an Insecure Permissions vulnerability, allowing unauthorized plugin downloads.
Can CVE-2018-1000080 be exploited remotely?
Yes, CVE-2018-1000080 can be exploited remotely if an attacker can craft the appropriate requests.