CVE-2017-18195 EXPLOIT
5.3
MEDIUM · CVSS 3.1 · EPSS 11.1% (pctl 96)
Patch early
A public exploit exists.
Description
An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog posts by POSTing requests to /index.php/tools/required/conversations/view_ajax with incremental 'cnvID' integers.
Scoring
| CVSS | 5.3 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 11.05% — more likely to be exploited than 96% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-02-26 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| concretecms | concrete cms |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Concrete5 CMS < 8.3.0 - Username / Comments Enumeration | 2018-02-27 |
References
- https://github.com/concrete5/concrete5/pull/6008/files
- https://github.com/concrete5/concrete5/releases/tag/8.3.0
- https://github.com/r3naissance/NSE/blob/master/http-vuln-cve2017-18195.nse
- https://www.exploit-db.com/exploits/44194/
- https://github.com/concrete5/concrete5/pull/6008/files
- https://github.com/concrete5/concrete5/releases/tag/8.3.0
- https://github.com/r3naissance/NSE/blob/master/http-vuln-cve2017-18195.nse
- https://www.exploit-db.com/exploits/44194/
→ the Explorer · watch your stack · NVD