peter bassill · operator
$ cve CVE-2018-15576 JSON

CVE-2018-15576 EXPLOIT

8.1
HIGH · CVSS 3.0 · EPSS 9.7% (pctl 95)

Patch early

A public exploit exists.

Description

An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in the decrypt function, if the attacker knows the key.

Scoring

CVSS8.1 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS9.68% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploityes
Published2018-08-24
Last modified2026-06-17

Affected (1)

VendorProduct
hazzardwebeasylogin pro

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD