ZeroHour

CVE-2024-36042

PoC
CVSS 3.1
9.8 critical
EPSS
<1%p59
Published
()
Modified
Description

Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.

Vendors
silverpeas
Products
silverpeas
Weakness
CWE-288
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.