First published: Fri Oct 12 2018(Updated: )
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Nuuo Nuuo Cms | <=3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17888 has been classified as a critical vulnerability due to its potential for arbitrary remote code execution.
To mitigate CVE-2018-17888, upgrade to a version of NUUO CMS that is later than 3.1.
All versions of NUUO CMS up to and including version 3.1 are affected by CVE-2018-17888.
CVE-2018-17888 could allow attackers to obtain the active session ID, enabling arbitrary remote code execution.
Yes, there are known exploits for CVE-2018-17888 that take advantage of the session identification mechanism.