CVE-2024-42850

CRITICAL

Silverpeas < 6.4.2 - Weak Password Requirements Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-42850. PoCs published by njmbb8.

AI-analyzed exploit summary The repository details a vulnerability in Silverpeas v6.4.2 and lower where password complexity requirements can be bypassed during a password change. The writeup includes technical details and screenshots demonstrating the issue, showing how a separate POST request updates the account without rechecking password complexity.

Description

An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.

Exploits (1)

nomisec WRITEUP 1 stars
by njmbb8 · poc
https://github.com/njmbb8/CVE-2024-42850

The repository details a vulnerability in Silverpeas v6.4.2 and lower where password complexity requirements can be bypassed during a password change. The writeup includes technical details and screenshots demonstrating the issue, showing how a separate POST request updates the account without rechecking password complexity.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Silverpeas v6.4.2 and lower
Auth required
Prerequisites: Access to a user account in Silverpeas
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory
https://github.com/njmbb8/CVE-2024-42850

Scores

CVSS v3 9.8
EPSS 0.4978
EPSS Percentile 97.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-521
Status published
Products (2)
org.silverpeas.core/silverpeas-core 0Maven
silverpeas/silverpeas < 6.4.2
Published Aug 16, 2024
Tracked Since Feb 18, 2026