Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.
CVSS
No CVSS.
References
Configurations
History
29 May 2025, 20:21
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/Silverpeas/Silverpeas-Core/tags - Product | |
References | () https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2d - Exploit | |
References | () https://silverpeas.org/ - Product | |
CPE | cpe:2.3:a:silverpeas:silverpeas:*:*:*:*:*:*:*:* | |
First Time |
Silverpeas silverpeas
Silverpeas |
03 Jun 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-03 06:15
Updated : 2025-05-29 20:21
NVD link : CVE-2024-36042
Mitre link : CVE-2024-36042
JSON object : View
Products Affected
silverpeas
- silverpeas
CWE
No CWE.