VulnerabilityModified
CVE-2018-18982
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution.
HIGH 8.8EPSS 60.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 60.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 60.79% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- nuuo/nuuo cms
- Source
- ics-cert@hq.dhs.gov
References
- https://ics-cert.us-cert.gov/advisories/ICSA-18-284-02Third Party Advisory, US Government Resource
- https://www.exploit-db.com/exploits/46449/Exploit, Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-284-02Third Party Advisory, US Government Resource
- https://www.exploit-db.com/exploits/46449/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.