CVE-2018-12642: High severity frox vulnerability
Published Jun 22, 2018
·Updated
Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
Affected Software
2 affected componentsFixes available
composer/froxlor/froxlor<0.9.40
0.9.40
Froxlor Froxlor<=0.9.39.5
Remediation
Event History
Jun 22, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
Description
May 13, 2022
Advisory Published
via GitHub·01:49 AM
Frequently Asked Questions
1
What is CVE-2018-12642?
CVE-2018-12642 is a vulnerability in Froxlor through version 0.9.39.5 that allows incorrect access control for tickets not owned by the current user.
2
How severe is CVE-2018-12642?
CVE-2018-12642 has a severity rating of 7.5, which is considered high.
3
What software is affected by CVE-2018-12642?
Froxlor version 0.9.39.5 is affected by CVE-2018-12642.
4
How can I fix CVE-2018-12642?
To fix CVE-2018-12642, it is recommended to update to a version of Froxlor that is not affected by the vulnerability.
5
Where can I find more information about CVE-2018-12642?
More information about CVE-2018-12642 can be found at the following link: [https://github.com/Froxlor/Froxlor/commit/aa881560cc996c38cbf8c20ee62854e27f72c73c](https://github.com/Froxlor/Froxlor/commit/aa881560cc996c38cbf8c20ee62854e27f72c73c)