CVE-2018-17368

An issue was discovered in PublicCMS V4.0.180825. For an invalid login attempt, the response length is different depending on whether the username is valid, which makes it easier to conduct brute-force attacks.
References
Link Resource
https://github.com/sanluan/PublicCMS/issues/18 Exploit Third Party Advisory
https://github.com/sanluan/PublicCMS/issues/18 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:publiccms:publiccms:4.0.180825:*:*:*:*:*:*:*

History

21 Nov 2024, 03:54

Type Values Removed Values Added
References () https://github.com/sanluan/PublicCMS/issues/18 - Exploit, Third Party Advisory () https://github.com/sanluan/PublicCMS/issues/18 - Exploit, Third Party Advisory

Information

Published : 2018-09-23 22:29

Updated : 2024-11-21 03:54


NVD link : CVE-2018-17368

Mitre link : CVE-2018-17368

CVE.ORG link : CVE-2018-17368


JSON object : View

Products Affected

publiccms

  • publiccms