CVE-2018-6460
User controlled input is not sufficiently filtered: an unauthenticated attacker can send a POST request to /status.js with the parameter func=$_APPLOG.Rfunc and extract sensitive information about the machine, including whether the user is connected to…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.0%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sensitive information including configuration. User controlled input is not sufficiently filtered: an unauthenticated attacker can send a POST request to /status.js with the parameter func=$_APPLOG.Rfunc and extract sensitive information about the machine, including whether the user is connected to a VPN, to which VPN he/she is connected, and what is their real IP address.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 10.98% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- anchorfree/hotspot shield
- Source
- cve@mitre.org
References
- https://blogs.securiteam.com/index.php/archives/3604Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/44042/Exploit, Third Party Advisory, VDB Entry
- https://blogs.securiteam.com/index.php/archives/3604Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/44042/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.