Логотип exploitDog
bind:CVE-2023-53923
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-53923

Количество 2

Количество 2

nvd логотип

CVE-2023-53923

около 2 месяцев назад

UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST request to /dist/admin/index.php with specific parameters to generate a new admin user with full system access.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33jq-r57w-5666

около 2 месяцев назад

UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST request to /dist/admin/index.php with specific parameters to generate a new admin user with full system access.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-53923

UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST request to /dist/admin/index.php with specific parameters to generate a new admin user with full system access.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-33jq-r57w-5666

UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST request to /dist/admin/index.php with specific parameters to generate a new admin user with full system access.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу