CVE-2018-17368: Publiccms
Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.
An issue was discovered in PublicCMS V4.0.180825. For an invalid login attempt, the response length is different depending on whether the username is valid, which makes it easier to conduct brute-force attacks.
Affected products
- Publiccms Publiccms: version 4.0.180825 only
Published 2018-09-23. Last modified 2026-06-17.