Vulnerability Details CVE-2018-8096
Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name":"isauthenticationenabled","Value":false' in an api/settings/setting-isauthenticationenabled PUT request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.059
EPSS Ranking 90.2%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2018-8096
-
cpe:2.3:a:datalust:seq:1.3.
-
cpe:2.3:a:datalust:seq:1.3.10
-
cpe:2.3:a:datalust:seq:1.3.11
-
cpe:2.3:a:datalust:seq:1.3.9
-
cpe:2.3:a:datalust:seq:1.4.10
-
cpe:2.3:a:datalust:seq:1.4.11
-
cpe:2.3:a:datalust:seq:1.4.12
-
cpe:2.3:a:datalust:seq:1.4.6
-
cpe:2.3:a:datalust:seq:1.4.7
-
cpe:2.3:a:datalust:seq:1.4.8
-
cpe:2.3:a:datalust:seq:1.4.9
-
cpe:2.3:a:datalust:seq:1.5.16
-
cpe:2.3:a:datalust:seq:1.5.17
-
cpe:2.3:a:datalust:seq:1.5.18
-
cpe:2.3:a:datalust:seq:1.5.19
-
cpe:2.3:a:datalust:seq:1.6.10
-
cpe:2.3:a:datalust:seq:1.6.11
-
cpe:2.3:a:datalust:seq:1.6.12
-
cpe:2.3:a:datalust:seq:1.6.13
-
cpe:2.3:a:datalust:seq:1.6.4
-
cpe:2.3:a:datalust:seq:1.6.5
-
cpe:2.3:a:datalust:seq:1.6.6
-
cpe:2.3:a:datalust:seq:1.6.7
-
cpe:2.3:a:datalust:seq:1.6.8
-
cpe:2.3:a:datalust:seq:1.6.9
-
cpe:2.3:a:datalust:seq:2.0.19
-
cpe:2.3:a:datalust:seq:2.1.21
-
cpe:2.3:a:datalust:seq:2.1.22
-
cpe:2.3:a:datalust:seq:2.2.8
-
cpe:2.3:a:datalust:seq:2.3.3
-
cpe:2.3:a:datalust:seq:2.3.4
-
cpe:2.3:a:datalust:seq:2.4.2
-
cpe:2.3:a:datalust:seq:3.0.30
-
cpe:2.3:a:datalust:seq:3.1.16
-
cpe:2.3:a:datalust:seq:3.1.17
-
cpe:2.3:a:datalust:seq:3.2.16
-
cpe:2.3:a:datalust:seq:3.3.20
-
cpe:2.3:a:datalust:seq:3.3.21
-
cpe:2.3:a:datalust:seq:3.3.22
-
cpe:2.3:a:datalust:seq:3.3.23
-
cpe:2.3:a:datalust:seq:3.4.17
-
cpe:2.3:a:datalust:seq:3.4.18
-
cpe:2.3:a:datalust:seq:3.4.20
-
cpe:2.3:a:datalust:seq:4.0.58
-
cpe:2.3:a:datalust:seq:4.0.60
-
cpe:2.3:a:datalust:seq:4.1.14
-
cpe:2.3:a:datalust:seq:4.1.16
-
cpe:2.3:a:datalust:seq:4.1.17
-
cpe:2.3:a:datalust:seq:4.2.470
-
cpe:2.3:a:datalust:seq:4.2.476