Skip to content

Latest commit

 

History

History
15 lines (9 loc) · 1.02 KB

README.md

File metadata and controls

15 lines (9 loc) · 1.02 KB

CVE-2024-42850

An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.

Writeup

Logging in with a single character password

When changing your password, upon submission of the new password, the password is first sent in a POST request to an endpoint which checks to ensure that the password is in compliance with complexity requirements.

Request to check conformity

After Silverpeas has confirmed that the password meets the requirements, a separate POST request is made to update the account with the password with no checks, leading to a possibility of setting a single character password.

Request to update account

Account update confirmation