CVE-2018-15658
Last modified
CVE-2018-15658 is a vulnerability of currently unknown severity. An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master.html, an attacker is able to see the markup that would be presented to an authenticated user. EPSS estimates a 1.78% chance of exploitation in the next 30 days.
Description
An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master.html, an attacker is able to see the markup that would be presented to an authenticated user. This is caused by the session validation occurring after the initial markup is loaded. This results in a list of unprotected API endpoints that disclose call logs, SMS logs, and user-account data.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| 42gears | Suremdm | < 2018-11-27 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-15658?
How severe is CVE-2018-15658?
How do I fix CVE-2018-15658?
Are you affected by CVE-2018-15658?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
