github.com
https://github.com/Kc57/JitBit_Helpdesk_Auth_Bypass CVE-2017-18486
HIGH
JitBit HelpDesk < 9.0.2 - Authentication Bypass
Record summary
CVE-2017-18486 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The shared secret can be used to escalate privileges by forging new tokens for any user. These tokens can be used to automatically log in as the affected user.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBJitBit HelpDesk < 9.0.2 - Authentication BypassExploitDB exploitby Kc57Not analyzed1 file
Repository PoCs
GitHubKc57/JitBit_Helpdesk_Auth_BypassRepository PoCby Kc57Stars: 3Not analyzed6 files
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-18486 packetstormsecurity.com
https://packetstormsecurity.com/files/144334/JitBit-Helpdesk-9.0.2-Broken-Authentication.html exploit-db.com
https://www.exploit-db.com/exploits/42776 trustedsec.com
https://www.trustedsec.com/2017/09/full-disclosure-jitbit-helpdesk-authentication-bypass-0-day