CVE-2018-16286: Critical severity lg supersign cms vulnerability
LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-16286?
CVE-2018-16286 is a vulnerability that allows authentication bypass in LG SuperSign CMS.
What is the severity of CVE-2018-16286?
CVE-2018-16286 has a severity level of critical, with a CVSS score of 9.8.
How does CVE-2018-16286 work?
CVE-2018-16286 allows an attacker to bypass authentication in LG SuperSign CMS by skipping the CAPTCHA requirement if a captcha:pass cookie is sent and by exploiting the limitation of only four digits for the PIN.
Is there a fix for CVE-2018-16286?
At the moment, there is no official fix or patch available for CVE-2018-16286. It is recommended to mitigate the vulnerability by implementing additional security measures and monitoring access to the affected LG SuperSign CMS.
Where can I find more information about CVE-2018-16286?
More information about CVE-2018-16286 can be found at the following URL: http://mamaquieroserpentester.blogspot.com/2018/09/multiple-vulnerabilities-in-lg.html