peter bassill · operator
$ cve CVE-2018-16606 JSON

CVE-2018-16606 EXPLOIT

6.5
MEDIUM · CVSS 3.0 · EPSS 5.9% (pctl 93)

Patch early

A public exploit exists.

Description

In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and their authors' personal information (Name, Email, Organization, and Position) by changing the value of Paper ID (the pid parameter).

Scoring

CVSS6.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS5.95% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-639
On CISA KEVno
Public exploityes
Published2018-09-06
Last modified2026-06-17

Affected (1)

VendorProduct
proconfproconf

Public exploits

SourceTitleDate
exploit-dbProConf 6.0 - Insecure Direct Object Reference (IDOR)2025-04-16

References

→ the Explorer  ·  watch your stack  ·  NVD