9.8
CVSSv3

CVE-2017-16935

Published: 24/11/2017 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Ametys prior to 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote malicious users to bypass intended access restrictions via a direct request to /plugins/core-ui/servercomm/messages.xml, as demonstrated by changing the admin password by obtaining account details via a users/search.json request, and then modifying the account via an editUser request.

Vulnerable Product Search on Vulmon Subscribe to Product

ametys ametys

Exploits

## Vulnerability Summary The following advisory describes a password reset vulnerability found in Ametys CMS version 402 Ametys is “a free and open source content management system (CMS) written in Java It is based on JSR-170 for content storage, Open Social for gadget rendering and a XML oriented framework” ## Credit An independent secur ...