CVE-2017-16935
CRITICALAmetys < 4.0.3 - Unauthenticated Access Control Bypass via Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-16935. PoCs published by SecuriTeam.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Ametys CMS 4.0.2, allowing unauthenticated users to reset passwords, including the administrator's, by leveraging insufficient authorization checks on specific endpoints.
Description
Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to bypass intended access restrictions via a direct request to /plugins/core-ui/servercomm/messages.xml, as demonstrated by changing the admin password by obtaining account details via a users/search.json request, and then modifying the account via an editUser request.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in Ametys CMS 4.0.2, allowing unauthenticated users to reset passwords, including the administrator's, by leveraging insufficient authorization checks on specific endpoints.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H