CVE-2018-20371
Last modified
CVE-2018-20371 is a vulnerability of currently unknown severity. PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated by "GET /login.html__passwd1" and "GET /login.html__passwd2" and so on.. EPSS estimates a 1.58% chance of exploitation in the next 30 days.
Description
PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated by "GET /login.html__passwd1" and "GET /login.html__passwd2" and so on.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Photorange Photo Vault Project | Photorange Photo Vault | 1.2 |
References
- https://www.vulnerability-lab.com/get_content.php?id=2110Exploit, Third Party Advisory
- https://www.vulnerability-lab.com/get_content.php?id=2110Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20371?
How severe is CVE-2018-20371?
How do I fix CVE-2018-20371?
Are you affected by CVE-2018-20371?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
