HTTP: Ektron CMS CVE-2018-12596 IAC

This signature detects attempts to exploit a known vulnerability against Ektron CMS. A successful attack can lead to security bypass.

Extended Description

Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages via the "activateuser.aspx" page, even if a page is located under the /WorkArea/ path, which is forbidden (normally available exclusively for local admins).

Affected Products

Episerver ektron_cms

References

CVE: CVE-2018-12596

Short Name
HTTP:MISC:EKTRON-CVE-2018-12596
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CMS CVE-2018-12596 Ektron IAC
Release Date
09/17/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3415
False Positive
Unknown
Vendors

Episerver

CVSS Score

7.5

Found a potential security threat?