SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-18982

NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution.

HIGH 8.8EPSS 60.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 60.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution.

CVSS 3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
60.79% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-89
Affected
nuuo/nuuo cms
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.