An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
http://silverpeas.com | product |
https://github.com/njmbb8/CVE-2024-42850 | third party advisory exploit |