CVE-2024-42850
CRITICALSilverpeas <6.4.2 - Auth Bypass
Title source: llmDescription
An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.4978
EPSS Percentile
97.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-521
Status
published
Products (2)
org.silverpeas.core/silverpeas-core
0Maven
silverpeas/silverpeas
< 6.4.2
Published
Aug 16, 2024
Tracked Since
Feb 18, 2026