CVE-2024-36042
9.8CRITICALSilverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.
Published: 6/3/2024Updated: 5/29/2025
Description
Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.
AI AnalysisPowered by AI
Affected Products
silverpeassilverpeas
References
- https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2dExploit
- https://github.com/Silverpeas/Silverpeas-Core/tagsProduct
- https://silverpeas.org/Product
- https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2dExploit
- https://github.com/Silverpeas/Silverpeas-Core/tagsProduct
- https://silverpeas.org/Product