Loading
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.
Use CWE-330, Nuuo vendor hub and Nuuo Cms product page to widen CVE-2018-17888 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-17936, CVE-2018-17934 and CVE-2018-17894 for nearby disclosures in the same product family.