CVE-2018-16979
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 3.0%
exploitation probability
3.0%top 14% of all CVEs
observed exploitation
nono source reports it
Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-2943.
Affected products
n/a · n/a