CVE-2018-10723: Critical severity directus 7 api vulnerability
Published May 5, 2018
·Updated
Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.
Affected Software
1 affected component
Rangerstudio Directus=6.4.9
Event History
May 5, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10723?
CVE-2018-10723 has a moderate severity rating due to the hardcoded admin password vulnerability.
2
How do I fix CVE-2018-10723?
To fix CVE-2018-10723, update to a version of Directus that does not include the hardcoded password.
3
What does CVE-2018-10723 affect?
CVE-2018-10723 affects Directus version 6.4.9 specifically.
4
What is the impact of exploiting CVE-2018-10723?
Exploiting CVE-2018-10723 allows unauthorized access to the Admin account due to the hardcoded password.
5
What should I do if I am using Directus 6.4.9 and cannot update?
If you cannot update Directus 6.4.9, change the admin password as soon as possible and restrict access to the application.