PT-2024-26859 · Unknown · Silverpeas

Chris Pritchard

·

Published

2024-06-03

·

Updated

2025-07-20

·

CVE-2024-36042

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Silverpeas versions prior to 6.3.5
Description The issue allows authentication bypass by omitting the Password field to AuthenticationServlet, potentially providing an unauthenticated user with superadmin access. This has been exploited in real-world incidents to gain access and escalate privileges.
Recommendations For versions prior to 6.3.5, update to version 6.3.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the AuthenticationServlet to minimize the risk of exploitation.

Exploit

Fix

LPE

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2024-36042
GHSA-4W54-WWC9-X62C

Affected Products

Silverpeas