Main
Vulnerability Database
Exploits
ID:10746 - Exploit for Input validation error in Swagger UI - CVE-2018-25031
ID:10746 - Exploit for Input validation error in Swagger UI - CVE-2018-25031
Published: October 25, 2024
Vulnerability identifier: #VU64011
Vulnerability risk: Low
CVE-ID: CVE-2018-25031
CWE-ID: CWE-20
Exploitation vector: Remote access
Vulnerable software:
Swagger UI
Swagger UI
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can trick the victim into opening a specially crafted URL to display remote OpenAPI definitions.
Remediation
Install updates from vendor's website.