CVE-2021-40616

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
14/06/2022
Last modified:
08/08/2023

Description

thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the background user management group authority is required.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:thinkcmf:thinkcmf:5.1.7:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools