CVE Vulnerabilities

CVE-2021-45786

Improper Authentication

Published: Mar 16, 2022 | Modified: Mar 22, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

In maccms v10, an attacker can log in through /index.php/user/login in the col and openid parameters to gain privileges.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Maccms Maccms 10.0 (including) 10.0 (including)

Potential Mitigations

References