CVE-2018-16606 EXPLOIT
6.5
MEDIUM · CVSS 3.0 · EPSS 5.9% (pctl 93)
Patch early
A public exploit exists.
Description
In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and their authors' personal information (Name, Email, Organization, and Position) by changing the value of Paper ID (the pid parameter).
Scoring
| CVSS | 6.5 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 5.95% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-639 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-09-06 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| proconf | proconf |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ProConf 6.0 - Insecure Direct Object Reference (IDOR) | 2025-04-16 |
References
- https://blog.ziaurrashid.com/idor-on-proconf-peer-reviewand-conference-management-system/
- https://packetstormsecurity.com/files/149259/IDOR-On-ProConf-Peer-Review-And-Conference-Management-6.0-File-Disclosure.html
- https://blog.ziaurrashid.com/idor-on-proconf-peer-reviewand-conference-management-system/
- https://packetstormsecurity.com/files/149259/IDOR-On-ProConf-Peer-Review-And-Conference-Management-6.0-File-Disclosure.html
→ the Explorer · watch your stack · NVD