7.5
CVSSv2

CVE-2018-3783

Published: 17/08/2018 Updated: 03/10/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A privilege escalation detected in flintcms versions <= 1.1.9 allows account takeover due to blind MongoDB injection in password reset.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

flintcms flintcms

Github Repositories

Blind noSQL injection case study lab based on CVE-2018-3783

nosqli-flintcms Blind noSQL injection case study lab based on CVE-2018-3783 (privilege escalation on flintcms 119) The vulnerability was originally discovered by Benoit Côté-Jodoin You can read original report on HackerOne Prerequisites docker-compose Limitation: We removed sendEmail function so that the server cannot se