CVE-2018-1000641: Critical severity yeswiki cercopitheque vulnerability
Published Aug 20, 2018
·Updated
YesWiki version <= cercopitheque beta 1 contains a PHP Object Injection vulnerability in Unserialising user entered parameter in i18n.inc.php that can result in execution of code, disclosure of information.
Affected Software
3 affected components
YesWiki YesWiki=2012-10-22-1
YesWiki YesWiki=2013-10-17-1
YesWiki YesWiki=2016-03-17-1
Remediation
Patch Available
Event History
Aug 20, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-1000641?
CVE-2018-1000641 is classified as a high severity vulnerability due to its potential for code execution and information disclosure.
2
How do I fix CVE-2018-1000641?
To mitigate CVE-2018-1000641, update YesWiki to a version beyond cercopitheque beta 1 to eliminate the PHP Object Injection vulnerability.
3
Who is affected by CVE-2018-1000641?
CVE-2018-1000641 affects YesWiki versions 2012-10-22-1, 2013-10-17-1, and 2016-03-17-1.
4
What is the main impact of CVE-2018-1000641?
The main impact of CVE-2018-1000641 is that it allows attackers to execute arbitrary code by exploiting PHP Object Injection.
5
When was CVE-2018-1000641 discovered?
CVE-2018-1000641 was disclosed in August 2018.