9
CVSSv2

CVE-2018-18387

Published: 29/10/2018 Updated: 03/10/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

playSMS up to and including 1.4.2 allows Privilege Escalation through Daemon abuse.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

playsms project playsms

Github Repositories

playSMS < = 1.4.2 - Privilege escalation

CVE-2018-18387 playSMS &lt; = 142 - Privilege escalation TMHC TEAM found a vulnerability that lead to a priviledge escalation through playSMS/web/initphp that can lead to a complete system compromise The attacker need to get access on the box where playSMS is installed and be able to edit playSMS related files, and the daemon must be run as root In the PHP code, refere