Assigner | mitre |
Updated | 2024-06-06 |
Description
Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.
References
https://github.com/Silverpeas/Silverpeas-Core/tags
https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2d