CVE-2018-17037

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/09/2018
Last modified:
03/10/2019

Description

user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ucms_project:ucms:1.4.6:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools