_RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pages via certain modified cookies, probably including (1) cUserRole, (2) cUserName, and (3) cUserID.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Realm_cms | Realm_project | 2.3 (including) | 2.3 (including) |