CVE-2018-15576 is a critical remote code execution (RCE) vulnerability affecting EasyLogin Pro through version 1.3.0, specifically within the Encryptor.php component. This flaw stems from an insecure unserialize call in the decrypt function, allowing an attacker to execute arbitrary code if they possess the encryption key. With a CVSS score of 8.1 (High), this vulnerability presents a significant risk due to its network-based attack vector and high impact on confidentiality, integrity, and availability. While not listed in CISA KEV, public exploit code is available on ExploitDB (EDB-45227), though there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.0CPE matchmatch criteria | cpe:2.3:a:hazzardweb:easylogin_pro:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.