CVE-2017-18486
Last modified
CVE-2017-18486 is a vulnerability of currently unknown severity. Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. EPSS estimates a 4.81% chance of exploitation in the next 30 days.
Description
Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The shared secret can be used to escalate privileges by forging new tokens for any user. These tokens can be used to automatically log in as the affected user.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jitbit | Helpdesk | < 9.0.3 |
References
- https://github.com/Kc57/JitBit_Helpdesk_Auth_BypassExploit, Third Party Advisory
- https://packetstormsecurity.com/files/144334/JitBit-Helpdesk-9.0.2-Broken-Authentication.htmlThird Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42776Exploit, Third Party Advisory, VDB Entry
- https://github.com/Kc57/JitBit_Helpdesk_Auth_BypassExploit, Third Party Advisory
- https://packetstormsecurity.com/files/144334/JitBit-Helpdesk-9.0.2-Broken-Authentication.htmlThird Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42776Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-18486?
How severe is CVE-2017-18486?
How do I fix CVE-2017-18486?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-18480cPanel before 62.0.4 does not enforce account ownership for …
- CVE-2017-18481cPanel before 62.0.4 allows stored XSS in the WHM Account Su…
- CVE-2017-18482cPanel before 62.0.4 allows resellers to use the WHM enqueue…
- CVE-2017-18483ANNKE SP1 HD wireless camera 3.4.1.1604071109 devices allow …
- CVE-2017-18484Cognitoys Dino devices allow XSS via the SSID.
- CVE-2017-18485Cognitoys Dino devices allow profiles_add.html CSRF.
- CVE-2017-18487The adsense-plugin (aka Google AdSense) plugin before 1.44 f…
- CVE-2017-18488The Backup Guard plugin before 1.1.47 for WordPress has mult…
- CVE-2017-18489The contact-form-7-sms-addon plugin before 2.4.0 for WordPre…
- CVE-2017-1849Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-18490The contact-form-multi plugin before 1.2.1 for WordPress has…
- CVE-2017-18491The contact-form-plugin plugin before 4.0.6 for WordPress ha…
Are you affected by CVE-2017-18486?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
