PT-2025-51952 · Ulicms · Ulicms

Mirabbas Ağalarov

·

Publicado

2025-12-17

·

Atualizado

2025-12-24

·

CVE-2023-53914

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UliCMS version 2023.1
Description An authentication bypass allows unauthenticated attackers to create administrative users. This is possible through mass assignment in the UserController by sending a crafted POST request to the ''index.php'' endpoint. Successful exploitation grants attackers full system access. The vulnerable parameter is not explicitly mentioned.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-53914

Produtos afetados

Ulicms