CVE-2018-0787High

ASP.NET Core Elevation of Privilege Vulnerability

Published
March 13, 2018
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An elevation of privilege vulnerability exists when a Kestrel web application fails to validate web requests. An attacker who successfully exploited this vulnerability could perform HTML injection attacks. To exploit the vulnerability, an attacker could send a specially crafted request, containing injected HTML, to the web application. The specially crafted request would initiate a "password reset" email to the target user. Depending on the target user email client, the injected HTML could trigger as soon as the target user opens the "password reset" e-mail. The security update addresses the vulnerability by correcting how a Kestrel web application validates web requests.

🎯 Affected products1

  • ASP.NET Core 2.0

✅ Remediation

KBCommit (Security Update)

🔗 References (2)