CVE-2018-16988: Critical severity XDMoD Open XDMoD vulnerability
An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in the plausible situation where the attacker knows that the victim has started a password-reset process (passreset.php, passwordreset.php, XDUser.php) in the past few minutes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16988?
CVE-2018-16988 is considered to have a high severity due to the potential for authentication bypass and account takeover.
How do I fix CVE-2018-16988?
To fix CVE-2018-16988, update Open XDMoD to a version higher than 7.5.0 or apply any available security patches from the vendor.
What are the implications of CVE-2018-16988 for my application?
The implications of CVE-2018-16988 include the risk of unauthorized access to user accounts if the vulnerability is exploited.
Which versions of Open XDMoD are affected by CVE-2018-16988?
Versions of Open XDMoD from 7.0.1 up to 7.5.0 are affected by CVE-2018-16988.
Can CVE-2018-16988 be exploited remotely?
Yes, CVE-2018-16988 can be exploited remotely if an attacker has knowledge of the victim's password reset process.