CVE-2024-36042
9.8CRITICALSilverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.
Publicado: 6/3/2024Atualizado: 5/29/2025
Descrição
Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.
Análise IADesenvolvido por IA
Produtos Afetados
silverpeassilverpeas
Referências
- https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2dExploit
- https://github.com/Silverpeas/Silverpeas-Core/tagsProduct
- https://silverpeas.org/Product
- https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2dExploit
- https://github.com/Silverpeas/Silverpeas-Core/tagsProduct
- https://silverpeas.org/Product