CVE Vulnerabilities

CVE-2018-1000551

Published: Jun 26, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Trovebox version <= 4.0.0-rc6 contains a PHP Type juggling vulnerability in album view component that can result in Authentication bypass. This attack appear to be exploitable via HTTP Request. This vulnerability appears to have been fixed in after commit 742b8edbe.

Affected Software

NameVendorStart VersionEnd Version
TroveboxTrovebox*3.0.0 (including)
TroveboxTrovebox4.0.0-rc2 (including)4.0.0-rc2 (including)
TroveboxTrovebox4.0.0-rc5 (including)4.0.0-rc5 (including)
TroveboxTrovebox4.0.0-rc6 (including)4.0.0-rc6 (including)

References