Security Advisory

CVE-2018-12596

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-10-10 21:00:00
Last updated 2024-08-05 08:38:06
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages via the "activateuser.aspx" page, even if a page is located under the /WorkArea/ path, which is forbidden (normally available exclusively for local admins).