CVE-2018-1000551

EUVD-2018-1940
Trovebox version <= 4.0.0-rc6 contains a PHP Type juggling vulnerability in album view component that can result in Authentication bypass. This attack appear to be exploitable via HTTP Request. This vulnerability appears to have been fixed in after commit 742b8edbe.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
Affected Products (NVD)
VendorProductVersion
troveboxtrovebox
𝑥
≤ 3.0.0
troveboxtrovebox
4.0.0:rc2
troveboxtrovebox
4.0.0:rc5
troveboxtrovebox
4.0.0:rc6
𝑥
= Vulnerable software versions