CVE-2024-36042

9.8CRITICAL

Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.

Publicado: 6/3/2024Atualizado: 5/29/2025

Descrição

Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.

Análise IADesenvolvido por IA

Produtos Afetados

silverpeassilverpeas

Referências