CVE-2018-12596
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 22%
from disclosure to weapon0 days
Published on NVDOct 10
1st PoCJun 21
exploitation probability
22%top 3% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages via the "activateuser.aspx" page, even if a page is located under the /WorkArea/ path, which is forbidden (normally available exclusively for local admins).
Affected products
n/a · n/apublic PoCs found — 3
githubgithub.com/alt3kx/CVE-2018-12596★ 0cve_referencewww.exploit-db.com/exploits/45577/unverifiedexploitdbwww.exploit-db.com/exploits/45577unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.