CVE-2018-16988
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in the plausible situation where the attacker knows that the victim has started a password-reset process (pass_reset.php, password_reset.php, XDUser.php) in the past few minutes.
Se descubrió un problema en Open XDMoD en la versión 7.5.0. Existe una omisión de autenticación (account takeover) debido a un mecanismo de restablecimiento de contraseña débil. Un ataque por fuerza bruta contra un valor de eliminación MD5 requiere sólo 600 suposiciones en la situación plausible en la que el atacante sabe que la víctima ha iniciado un proceso de restablecimiento de contraseña (pass_reset.php, password_reset.php, XDUser.php) en los últimos minutos.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-09-13 CVE Reserved
- 2019-05-02 CVE Published
- 2024-03-23 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-640: Weak Password Recovery Mechanism for Forgotten Password
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/grymer/CVE/blob/master/CVE-2018-16988.md | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xdmod Search vendor "Xdmod" | Open Xdmod Search vendor "Xdmod" for product "Open Xdmod" | <= 7.0.1 Search vendor "Xdmod" for product "Open Xdmod" and version " <= 7.0.1" | - |
Affected
| ||||||
Xdmod Search vendor "Xdmod" | Open Xdmod Search vendor "Xdmod" for product "Open Xdmod" | 7.5.0 Search vendor "Xdmod" for product "Open Xdmod" and version "7.5.0" | - |
Affected
| ||||||
Xdmod Search vendor "Xdmod" | Open Xdmod Search vendor "Xdmod" for product "Open Xdmod" | 7.5.0 Search vendor "Xdmod" for product "Open Xdmod" and version "7.5.0" | rc1 |
Affected
| ||||||
Xdmod Search vendor "Xdmod" | Open Xdmod Search vendor "Xdmod" for product "Open Xdmod" | 7.5.0 Search vendor "Xdmod" for product "Open Xdmod" and version "7.5.0" | rc2 |
Affected
|