CVE-2018-1000501
CRITICALInstant Update CMS <v0.3.3 - Privilege Escalation
Title source: llmDescription
Instant Update CMS contains a Password Reset Vulnerability vulnerability in /iu-application/controllers/administration/auth.php that can result in Account Tackover. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in v0.3.3.
Scores
CVSS v3
9.8
EPSS
0.0047
EPSS Percentile
64.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-640
Status
published
Products (1)
instant-update/instant_update_cms
< 0.3.3
Published
Jun 26, 2018
Tracked Since
Feb 18, 2026