CVE-2021-45347

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
14/02/2022
Last modified:
23/02/2022

Description

An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by changing the user name in the cookie to use any password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zzcms:zzcms:8.2:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools