CVE-2018-7581: Weblogexpert Weblog Expert
High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.
\ProgramData\WebLog Expert\WebServer\WebServer.cfg in WebLog Expert Web Server Enterprise 9.4 has weak permissions (BUILTIN\Users:(ID)C), which allows local users to set a cleartext password and login as admin.
Affected products
- Weblogexpert Weblog Expert: version 9.4 only
Published 2018-03-09. Last modified 2026-06-17.