Record summary

CVE-2017-18486 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The shared secret can be used to escalate privileges by forging new tokens for any user. These tokens can be used to automatically log in as the affected user.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Proofs of concept

2

Catalogued exploits

ExploitDBJitBit HelpDesk < 9.0.2 - Authentication BypassExploitDB exploitby Kc57Not analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubKc57/JitBit_Helpdesk_Auth_BypassRepository PoCby Kc57Stars: 3Not analyzed6 files

12.7 KiB

GitHub

PoC details

References

5