CVE-2024-36042

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/06/2024
Last modified:
29/05/2025

Description

Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:silverpeas:silverpeas:*:*:*:*:*:*:*:* 6.3.5 (excluding)