CVE-2018-12596
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages via the "activateuser.aspx" page, even if a page is located under the /WorkArea/ path, which is forbidden…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 22.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages via the "activateuser.aspx" page, even if a page is located under the /WorkArea/ path, which is forbidden (normally available exclusively for local admins).
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 22.38% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- episerver/ektron cms
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2018/Oct/15Exploit, Mailing List, Mitigation, Patch, Third Party Advisory
- https://github.com/alt3kx/CVE-2018-12596Exploit, Patch, Third Party Advisory
- https://medium.com/%40alt3kx/ektron-content-management-system-cms-9-20-sp2-remote-re-enabling-users-cve-2018-12596-bdf1e3a05158
- https://www.exploit-db.com/exploits/45577/Exploit, Mitigation, Patch, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Oct/15Exploit, Mailing List, Mitigation, Patch, Third Party Advisory
- https://github.com/alt3kx/CVE-2018-12596Exploit, Patch, Third Party Advisory
- https://medium.com/%40alt3kx/ektron-content-management-system-cms-9-20-sp2-remote-re-enabling-users-cve-2018-12596-bdf1e3a05158
- https://www.exploit-db.com/exploits/45577/Exploit, Mitigation, Patch, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.