Vulnerability Details CVE-2018-19437
UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.0%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 4.0
Products affected by CVE-2018-19437
-
cpe:2.3:a:ucms_project:ucms:1.4.7