CVE-2018-11511
Description
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.
In plain language
AI Act nowCVE-2018-11511 is a SQL injection weakness in ASUSTOR ADM’s photo gallery “tree list” feature that can let an attacker tamper with the app’s database; if your business uses ASUSTOR ADM 3.1.0.RFQ3 and that photo gallery/API endpoint is reachable, you should worry and act now.
CVE-2018-11511 is a SQL injection (CWE-89) in ASUSTOR ADM 3.1.0.RFQ3 photo gallery tree list functionality (photo-gallery/api/album/tree_lists/) where the album_id or scope parameters can be injected and executed by the backend.
What to do now
- Check your ASUSTOR ADM version and confirm you are running ASUSTOR ADM 3.1.0.RFQ3.
- Identify whether the photo gallery feature is enabled and whether the photo-gallery/api/album/tree_lists endpoint is reachable from outside your network (the internet or any exposed port).
- If you have ASUSTOR ADM 3.1.0.RFQ3, look for an ADM update that addresses CVE-2018-11511; no fixed version is known from the available information, so contact ASUSTOR support or your managed hosting/IT vendor for the specific mitigation.
- If the endpoint is reachable externally and you cannot update immediately, restrict access so it is not reachable from the internet (block the exposed service/port or remove external access to the photo gallery/API).
- Review photo gallery/API access logs for unusual requests to the tree list API paths, and monitor for continued probing attempts.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-11511 and every CVE in our database. Create a free account — no credit card required.
Create Free Account