CVE-2018-18254: Capmon Access Manager

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in CapMon Access Manager 5.4.1.1005. An unprivileged user can read the cal_whitelist table in the Custom App Launcher (CAL) database, and potentially gain privileges by placing a Trojan horse program at an app pathname.

Affected products

  • Capmon Access Manager: up to and including 5.4.1.1005

Published 2019-03-15. Last modified 2026-06-17.