RULE(RULE ID:323773)

Rule General Information
Release Date: 2019-11-28
Rule Name: Navigate CMS Authentication Bypass Vulnerability (CVE-2018-17552)
Severity:
CVE ID:
Rule Protection Details
Description: SQL Injection inrenh login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: ExploitDB:45561
https://github.com/NavigateCMS/Navigate-CMS/commit/6df73ccca64253a5e81c23356943fae50ffc836f
https://github.com/rapid7/metasploit-framework/pull/10704
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://github.com/NavigateCMS/Navigate-CMS/commit/6df73ccca64253a5e81c23356943fae50ffc836f