PT-2022-11280 · Thinkcmf · Thinkcmf

Swagtimeaoop

·

Published

2022-06-14

·

Updated

2023-08-08

·

CVE-2021-40616

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions thinkcmf version 5.1.7
Description The issue allows an attacker to modify the password of the administrator account with id 1 through the background user management group permissions. This is possible when the background user management group authority is required.
Recommendations For thinkcmf version 5.1.7, restrict access to the background user management group permissions to minimize the risk of exploitation. As a temporary workaround, consider disabling the background user management group authority until a patch is available.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-40616
GHSA-V25C-8349-V2Q3

Affected Products

Thinkcmf