CVE-2018-18286: SQL Injection
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the changepwd interface. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18286?
CVE-2018-18286 is classified as a high-severity vulnerability due to its potential for unauthorized database access.
How do I fix CVE-2018-18286?
To fix CVE-2018-18286, users should update their CMG Suite to the latest version that addresses this SQL injection vulnerability.
What platforms are affected by CVE-2018-18286?
CVE-2018-18286 affects versions of CMG Suite 8.4 SP2 and earlier.
Can CVE-2018-18286 be exploited remotely?
Yes, CVE-2018-18286 can be exploited by an unauthenticated attacker due to insufficient input validation.
What type of attack does CVE-2018-18286 enable?
CVE-2018-18286 enables SQL injection attacks that can extract sensitive information from the database.