描述
Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.
AI分析AI驱动
受影响产品
silverpeassilverpeas
参考资料
- https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2dExploit
- https://github.com/Silverpeas/Silverpeas-Core/tagsProduct
- https://silverpeas.org/Product
- https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2dExploit
- https://github.com/Silverpeas/Silverpeas-Core/tagsProduct
- https://silverpeas.org/Product