CVE-2018-1000501 describes a critical password reset vulnerability in Instant Update CMS, specifically within the /iu-application/controllers/administration/auth.php component, affecting versions prior to 0.3.3. This flaw allows for unauthenticated account takeover due to its network-exploitable nature and low attack complexity, posing a severe risk to confidentiality, integrity, and availability with a CVSS score of 9.8. While no public exploit code (Metasploit, Nuclei, ExploitDB) or active exploitation has been observed, and community discussion is minimal, organizations using affected versions should prioritize patching to mitigate this significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.3.3CPE matchmatch criteria | cpe:2.3:a:instant-update:instant_update_cms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.