Vulnerability Description
PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated by "GET /login.html__passwd1" and "GET /login.html__passwd2" and so on.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Photorange Photo Vault Project | Photorange Photo Vault | 1.2 |
Related Weaknesses (CWE)
References
- https://www.vulnerability-lab.com/get_content.php?id=2110ExploitThird Party Advisory
- https://www.vulnerability-lab.com/get_content.php?id=2110ExploitThird Party Advisory
FAQ
What is CVE-2018-20371?
CVE-2018-20371 is a vulnerability with a CVSS score of 9.8 (CRITICAL). PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated...
How severe is CVE-2018-20371?
CVE-2018-20371 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-20371?
Check the references section above for vendor advisories and patch information. Affected products include: Photorange Photo Vault Project Photorange Photo Vault.