CVE Vulnerabilities

CVE-2018-1000551

Published: Jun 26, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Trovebox version <= 4.0.0-rc6 contains a PHP Type juggling vulnerability in album view component that can result in Authentication bypass. This attack appear to be exploitable via HTTP Request. This vulnerability appears to have been fixed in after commit 742b8edbe.

Affected Software

Name Vendor Start Version End Version
Trovebox Trovebox * 3.0.0 (including)
Trovebox Trovebox 4.0.0-rc2 (including) 4.0.0-rc2 (including)
Trovebox Trovebox 4.0.0-rc5 (including) 4.0.0-rc5 (including)
Trovebox Trovebox 4.0.0-rc6 (including) 4.0.0-rc6 (including)

References