MEDIUM
These vulnerabilities require administrative privileges to exploit
Published Dec 3, 2018
4.8
MEDIUMCVSS 3.0
EPSS 2.58%
Description
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:14: via POST request variable classes
Affected products
- Vendor n/a Product Arigato Autoresponder and Newsletter Defaultn/a
- Version unspecifiedStatusaffectedConstraints<=2.5.1.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Arigato Autoresponder and Newsletter | n/a |
|
- ≥ 2.5.0 · < 2.5.1.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://www.vapidlabs.com/advisory.php?v=203 x_refsource_MISCExploitThird Party Advisory
- https://wordpress.org/plugins/bft-autoresponder/ x_refsource_MISCProduct
- https://www.exploit-db.com/exploits/45434/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| http://www.vapidlabs.com/advisory.php?v=203 | x_refsource_MISCExploitThird Party Advisory | |
| https://wordpress.org/plugins/bft-autoresponder/ | x_refsource_MISCProduct | |
| https://www.exploit-db.com/exploits/45434/ | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner larry_cashdollar
Published Dec 3, 2018
Updated Aug 5, 2024
Reserved Dec 3, 2018
Link CVE-2018-1002006
CISA Vulnrichment
Updated n/a