9.8

CVE-2024-36042

Exploit
Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SilverpeasSilverpeas Version < 6.3.5
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.94% 0.561
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-288 Authentication Bypass Using an Alternate Path or Channel

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2d
Exploit
https://github.com/Silverpeas/Silverpeas-Core/tags
Product
https://silverpeas.org/
Product