PoC Index

CVE-2018-17246

CRITICAL 9.8EPSS 82.3%

Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
82.25% chance of exploitation in the next 30 days, 100th percentile
Nuclei
critical
Published
2018-12-20
Updated
2024-08-05

Proof-of-concept exploits (1)

Nuclei templates (1)

Vulhub environments (1)

Exploit collections (2)

References

Related