CVE-2018-1000812 describes a weak password recovery mechanism in Artica Integria IMS version 5.0 MR56 Package 58 and likely earlier versions. This vulnerability, found in general/password_recovery.php, allows for network-based exploitation with high complexity, potentially leading to full user account takeover with high impact on confidentiality, integrity, and availability. While no public exploits (Metasploit, Nuclei, ExploitDB) are currently available and there is no evidence of active exploitation or significant community discussion, the vulnerability has been patched in versions released after commit f2ff0ba821644acecb893483c86a9c4d3bb75047.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.0CPE matchmatch criteria | cpe:2.3:a:artica:integria_ims:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.