First published: Mon Feb 14 2022(Updated: )
An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by changing the user name in the cookie to use any password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zzcms Zzcms | =8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security issue is CVE-2021-45347.
The severity rating of CVE-2021-45347 is high (7.5).
The affected software version is zzcms 8.2.
The vulnerability in zzcms 8.2 allows a malicious user to bypass authentication by changing the user name in the cookie.
There is currently no known fix available for CVE-2021-45347. It is recommended to update to a newer version of the software if and when a patch becomes available.