CVE-2024-36042
9.8CRITICALSilverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.
Опубликовано: 6/3/2024Обновлено: 5/29/2025
Описание
Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.
ИИ-АнализНа базе ИИ
Затронутые продукты
silverpeassilverpeas
Ссылки
- https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2dExploit
- https://github.com/Silverpeas/Silverpeas-Core/tagsProduct
- https://silverpeas.org/Product
- https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2dExploit
- https://github.com/Silverpeas/Silverpeas-Core/tagsProduct
- https://silverpeas.org/Product