CVE-2022-23383 Information
Jun 07, 2022
cve
Description
YzmCMS v6.3 is affected by broken access control. Without login unauthorized access to the user’s personal home page can be realized. It is necessary to judge the user’s login status before accessing the personal home page but the vulnerability can access other users’ home pages through the non login status because real authentication is not carried out.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Reference
http://yzmcms.com https://down.chinaz.com/soft/37810.htm https://www.cnvd.org.cn/user/myreport/6499961
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
9.1
Share on: