ZeroHour

CVE-2023-43154

CVSS 3.1
9.8 critical
EPSS
<1%p60
Published
()
Modified
Description

In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account.

Vendors
macs cms project
Products
macs cms
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.