CVE-2024-36042
9.8CRITICALSilverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.
Publicado: 6/3/2024Actualizado: 5/29/2025
Descripción
Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.
Análisis IAImpulsado por IA
Productos Afectados
silverpeassilverpeas
Referencias
- https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2dExploit
- https://github.com/Silverpeas/Silverpeas-Core/tagsProduct
- https://silverpeas.org/Product
- https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2dExploit
- https://github.com/Silverpeas/Silverpeas-Core/tagsProduct
- https://silverpeas.org/Product