CVE-2024-36042

CRITICAL9.8EPSS 0.13%

Silverpeas authentication bypass

Published: 6/3/2024Modified: 7/5/2024
Also known as:GHSA-4w54-wwc9-x62c

Description

Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (6)