CVE-2018-1000501

CRITICAL

Instant Update CMS <v0.3.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Instant Update CMS contains a Password Reset Vulnerability vulnerability in /iu-application/controllers/administration/auth.php that can result in Account Tackover. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in v0.3.3.

Scores

CVSS v3 9.8
EPSS 0.0047
EPSS Percentile 64.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-640
Status published
Products (1)
instant-update/instant_update_cms < 0.3.3
Published Jun 26, 2018
Tracked Since Feb 18, 2026