CVE-2018-13040 describes a Cross-Site Request Forgery (CSRF) vulnerability in OpenSID 18.06-pasca, affecting opendesa and opensid products. This high-severity flaw (CVSS 8.8) allows an unauthenticated attacker to add an administrative account by tricking a logged-in administrator into visiting a malicious link. While the potential impact is significant, leading to full compromise (confidentiality, integrity, availability), there is currently no public exploit code, Metasploit module, or Nuclei template available, and it is not listed on the KEV catalog. Community discussion and media coverage are also minimal, suggesting low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
18.06-pascaCPE matchmatch criteria | cpe:2.3:a:opendesa:opensid:18.06-pasca:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.