CVE-2018-25087

LOW

Arborator Server < 2018-10-20 - Denial of Service via Project Parameter in project.cgi

Title source: llm
STIX 2.1

Description

A vulnerability classified as problematic was found in Arborator Server. This vulnerability affects the function start of the file project.cgi. The manipulation of the argument project leads to denial of service. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The patch is identified as cdbdbcbd491db65e9d697ab4365605fdfab1a604. It is recommended to apply a patch to fix this issue. VDB-230662 is the identifier assigned to this vulnerability.

References (3)

Core 3
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.230662
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.230662

Scores

CVSS v3 3.5
EPSS 0.0090
EPSS Percentile 55.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (1)
arborator_server_project/arborator_server < 2018-10-20
Published Jun 06, 2023
Tracked Since Feb 18, 2026