CVE Vulnerabilities

CVE-2024-36042

Authentication Bypass Using an Alternate Path or Channel

Published: Jun 03, 2024 | Modified: May 29, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Silverpeas Silverpeas * 6.3.5 (excluding)

Potential Mitigations

References