CVE-2023-43154
Summary
| CVE | CVE-2023-43154 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-27 15:19:00 UTC |
| Updated | 2023-10-02 16:51:00 UTC |
| Description | In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account. |
Risk And Classification
Problem Types: CWE-843
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Macs Cms Project | Macs Cms | 1.1.4f | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PHP Type Confusion Vulnerability Leading to Administrator Account Takeover via Authentication Bypass - CXSecurity.com | MISC | cxsecurity.com | |
| GitHub - ally-petitt/CVE-2023-43154-PoC: PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover. | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.