605
VMScore

CVE-2018-8718

Published: 27/03/2018 Updated: 04/03/2019
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 8 | Impact Score: 5.9 | Exploitability Score: 2.1
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudson.tasks.Mailer/sendTestMail request.

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins mailer

Vendor Advisories

Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 120 for Jenkins 2111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudsontasksMailer/sendTestMail request ...

Exploits

# Exploit Title : Jenkins mailer plugin < 120 - Cross-Site Request Forgery # Date : 2018-06-05 # Exploit Author : Kl3_GMjq6 # Vendor Homepage : jenkinsio/ # Software Link : [updatesjenkinsio/download/plugins/mailer/120/mailerhpi] # Version: [Below Version 120 (11 ~ 120) ] # Ref: jenkinsio/security/advisory/2018- ...
Jenkins Mailer plugin versions prior to 120 suffer from a cross site request forgery vulnerability ...

Github Repositories

POC of CVE-2018-8718 + tool

################################################### #Exploit Title : [Jenkins] mailer plugin CSRF Vulnerability - Send CSRF MAIL #Date : [2018/06/05] #Exploit Author : [Yeom Geun Cheol] #Vendor Homepage : [jenkinsio/] #Software Link : [updatesjenkinsio/download/plugins/mailer/120/mailerhpi] #Version: [Below Version 120 (11 ~ 120) ] #Tested on : [Linux ,