CVE-2017-16935

CRITICAL

Ametys < 4.0.3 - Unauthenticated Access Control Bypass via Direct Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-16935. PoCs published by SecuriTeam.

AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Ametys CMS 4.0.2, allowing unauthenticated users to reset passwords, including the administrator's, by leveraging insufficient authorization checks on specific endpoints.

Description

Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to bypass intended access restrictions via a direct request to /plugins/core-ui/servercomm/messages.xml, as demonstrated by changing the admin password by obtaining account details via a users/search.json request, and then modifying the account via an editUser request.

Exploits (1)

exploitdb WORKING POC
by SecuriTeam · webappsphp
https://www.exploit-db.com/exploits/44050

This exploit demonstrates an authentication bypass vulnerability in Ametys CMS 4.0.2, allowing unauthenticated users to reset passwords, including the administrator's, by leveraging insufficient authorization checks on specific endpoints.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Ametys CMS 4.0.2
No auth needed
Prerequisites: Network access to the target Ametys CMS instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://blogs.securiteam.com/index.php/archives/3517
Issue Tracking, Vendor Advisory x_refsource_misc
https://issues.ametys.org/browse/RUNTIME-2582

Scores

CVSS v3 9.8
EPSS 0.0766
EPSS Percentile 93.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
ametys/ametys < 4.0.3
Published Nov 24, 2017
Tracked Since Feb 18, 2026