CVE-2024-42850
CRITICALSilverpeas < 6.4.2 - Weak Password Requirements Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-42850. PoCs published by njmbb8.
AI-analyzed exploit summary The repository details a vulnerability in Silverpeas v6.4.2 and lower where password complexity requirements can be bypassed during a password change. The writeup includes technical details and screenshots demonstrating the issue, showing how a separate POST request updates the account without rechecking password complexity.
Description
An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.
Exploits (1)
The repository details a vulnerability in Silverpeas v6.4.2 and lower where password complexity requirements can be bypassed during a password change. The writeup includes technical details and screenshots demonstrating the issue, showing how a separate POST request updates the account without rechecking password complexity.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H