CVE-2018-17888: Critical severity nuuo cms vulnerability
Published Oct 12, 2018
·Updated
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.
Affected Software
1 affected component
NUUO NUUO CMS<=3.1
Remediation
Patch Available
Event History
Oct 12, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-17888?
CVE-2018-17888 has been classified as a critical vulnerability due to its potential for arbitrary remote code execution.
2
How do I fix CVE-2018-17888?
To mitigate CVE-2018-17888, upgrade to a version of NUUO CMS that is later than 3.1.
3
What versions of NUUO CMS are affected by CVE-2018-17888?
All versions of NUUO CMS up to and including version 3.1 are affected by CVE-2018-17888.
4
What type of attack is possible with CVE-2018-17888?
CVE-2018-17888 could allow attackers to obtain the active session ID, enabling arbitrary remote code execution.
5
Are there known exploits for CVE-2018-17888?
Yes, there are known exploits for CVE-2018-17888 that take advantage of the session identification mechanism.