Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Link | Tags |
---|---|
https://silverpeas.org/ | product |
https://github.com/Silverpeas/Silverpeas-Core/tags | product |
https://gist.github.com/ChrisPritchard/4b6d5c70d9329ef116266a6c238dcb2d | exploit |