Описание
thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the background user management group authority is required.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:thinkcmf:thinkcmf:5.1.7:*:*:*:*:*:*:*
EPSS
Процентиль: 31%
0.00121
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-425
Связанные уязвимости
EPSS
Процентиль: 31%
0.00121
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-425