PT-2022-11280 · Thinkcmf · Thinkcmf
Swagtimeaoop
·
Published
2022-06-14
·
Updated
2023-08-08
·
CVE-2021-40616
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
thinkcmf version 5.1.7
Description
The issue allows an attacker to modify the password of the administrator account with
id 1 through the background user management group permissions. This is possible when the background user management group authority is required.Recommendations
For thinkcmf version 5.1.7, restrict access to the background user management group permissions to minimize the risk of exploitation. As a temporary workaround, consider disabling the background user management group authority until a patch is available.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Thinkcmf