Authentication Bypass Vulnerability in Silverpeas
CVE-2024-36042
9.8CRITICAL
What is CVE-2024-36042?
An authentication bypass vulnerability exists in Silverpeas, allowing attackers to gain unauthorized access to superadmin functionalities. By omitting the Password field within the AuthenticationServlet, an unauthenticated user could potentially exploit this flaw, resulting in elevated privileges and access to sensitive areas of the system. This vulnerability affects Silverpeas versions prior to 6.3.5 and poses a significant risk to the security of installations that do not implement the necessary updates.