CVE-2018-6835
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.
- Affected products
- Etherpad Lite
- Etherpad
- < 1.6.3
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 2.3% (82th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2018-02-08
CVE-2018-6835 at NVD
1 known exploit for CVE-2018-6835
Proof-of-concept code and exploit modules indexed by Sploitus