Описание
ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).
Ссылки
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.4.3 (исключая)
cpe:2.3:a:impresscms:impresscms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 70%
0.00623
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-843
Связанные уязвимости
EPSS
Процентиль: 70%
0.00623
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-843