CVE-2018-18286
Last modified
CVE-2018-18286 is a vulnerability of currently unknown severity. SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the changepwd interface. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts.. EPSS estimates a 1.84% chance of exploitation in the next 30 days.
Description
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the changepwd interface. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Mitel | Cmg Suite | <= 8.4 | — |
| Mitel | Cmg Suite | 8.4 | Sp2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-18286?
How severe is CVE-2018-18286?
How do I fix CVE-2018-18286?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-18276XSS exists in the ProFiles 1.5 component for Joomla! via the…
- CVE-2018-1828IBM Rational Collaborative Lifecycle Management 6.0 through …5.4
- CVE-2018-18281Since Linux kernel version 3.2, the mremap() syscall perform…
- CVE-2018-18282Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error p…
- CVE-2018-18284Artifex Ghostscript 9.25 and earlier allows attackers to byp…
- CVE-2018-18285SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earli…
- CVE-2018-18287On ASUS RT-AC58U 3.0.0.4.380_6516 devices, remote attackers …
- CVE-2018-18288CrushFTP through 8.3.0 is vulnerable to credentials theft vi…6.1
- CVE-2018-18289The MESILAT Zabbix plugin before 1.1.15 for Atlassian Conflu…
- CVE-2018-1829IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable…5.4
- CVE-2018-18290An issue was discovered in nc-cms through 2017-03-10. index.…
- CVE-2018-18291A cross site scripting (XSS) vulnerability on ASUS RT-AC58U …
Are you affected by CVE-2018-18286?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
