peter bassill · operator
$ cve CVE-2019-18418 JSON

CVE-2019-18418 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 4% (pctl 90)

Patch early

A public exploit exists.

Description

clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-384
On CISA KEVno
Public exploityes
Published2019-10-24
Last modified2026-06-17

Affected (1)

VendorProduct
clonosclonos

Public exploits

SourceTitleDate
exploit-dbClonOs WEB UI 19.09 - Improper Access Control2019-10-25

References

→ the Explorer  ·  watch your stack  ·  NVD