← Vulnerability feed

Vulnerability record · CVE-2024-36042 · published 3 June 2024

CVE-2024-36042: Silverpeas authentication bypass via alternate path vulnerability

Silverpeas · Silverpeas

Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.

9.8 CVSS 3.1 Critical EPSS 0.94% · top 40.5% CWE-288 · Authentication bypass via alternate path
9.8CVSS 3.1 base score
0.94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-36042 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2018-19586Silverpeas path traversal vulnerabilitySilverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because cor…EPSS 5.0%9.8CVE-2024-42850Silverpeas weak password requirements vulnerabilityAn issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.EPSS 1.4%8.8CVE-2023-47322Silverpeas cross-site request forgery vulnerabilityThe "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administr…EPSS 0.40%8.8CVE-2023-47326Silverpeas cross-site request forgery vulnerabilitySilverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function.EPSS 0.38%8.1CVE-2023-47320Silverpeas incorrect authorization vulnerabilitySilverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function o…EPSS 0.72%7.5CVE-2024-48814Silverpeas sql injection vulnerabilitySQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywher…EPSS 0.54%7.5CVE-2023-47323Silverpeas vulnerabilityThe notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all …EPSS 0.77%6.5CVE-2025-46047Silverpeas improper input validation vulnerabilityA User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determin…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2024-36042), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.