CVE-2018-18941

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
31/01/2019
Last modified:
24/08/2020

Description

In Vignette Content Management version 6, it is possible to gain remote access to administrator privileges by discovering the admin password in the vgn/ccb/user/mgmt/user/edit/0,1628,0,00.html?uid=admin HTML source code, and then creating a privileged user account. NOTE: this product is discontinued.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vignette:content_management:6:*:*:*:*:*:*:*