Vulnerability CVE-2022-23383


Published: 2022-03-10

Description:
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.

Type:

CWE-287

(Improper Authentication)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.4/10
4.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None
Affected software
Yzmcms -> Yzmcms 

 References:
http://yzmcms.com
https://down.chinaz.com/soft/37810.htm
https://www.cnvd.org.cn/user/myreport/6499961

Copyright 2024, cxsecurity.com

 

Back to Top