CVE-2018-17368: Medium severity sanluan publiccms vulnerability
Published Sep 23, 2018
·Updated
An issue was discovered in PublicCMS V4.0.180825. For an invalid login attempt, the response length is different depending on whether the username is valid, which makes it easier to conduct brute-force attacks.
Affected Software
1 affected component
PublicCMS publiccms=4.0.180825
Event History
Sep 23, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue in PublicCMS V4.0.180825?
The vulnerability ID for this issue in PublicCMS V4.0.180825 is CVE-2018-17368.
2
What is the severity level of CVE-2018-17368?
The severity level of CVE-2018-17368 is medium.
3
How does CVE-2018-17368 make it easier to conduct brute-force attacks?
CVE-2018-17368 makes it easier to conduct brute-force attacks because the response length for an invalid login attempt is different depending on whether the username is valid.
4
What software versions are affected by CVE-2018-17368?
The PublicCMS V4.0.180825 version is affected by CVE-2018-17368.
5
Is there a fix for CVE-2018-17368?
Yes, there is a fix for CVE-2018-17368. It can be found in the reference link provided.