CVE-2024-42849
MEDIUMSilverpeas < 6.4.2 - Denial of Service via Password Change Function
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-42849. PoCs published by njmbb8.
AI-analyzed exploit summary The repository provides a detailed technical writeup and proof-of-concept steps for CVE-2024-42849, a denial-of-service vulnerability in Silverpeas v6.4.2 and lower. The vulnerability is triggered by sending a 1MB-long password string, overwhelming system resources during password hashing.
Description
An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.
Exploits (1)
The repository provides a detailed technical writeup and proof-of-concept steps for CVE-2024-42849, a denial-of-service vulnerability in Silverpeas v6.4.2 and lower. The vulnerability is triggered by sending a 1MB-long password string, overwhelming system resources during password hashing.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H