In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account.
History

Tue, 24 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-09-26T00:00:00

Updated: 2024-09-24T18:50:29.181Z

Reserved: 2023-09-18T00:00:00

Link: CVE-2023-43154

cve-icon Vulnrichment

Updated: 2024-08-02T19:37:23.001Z

cve-icon NVD

Status : Analyzed

Published: 2023-09-27T15:19:33.323

Modified: 2023-10-02T16:51:34.027

Link: CVE-2023-43154

cve-icon Redhat

No data.