CVE-2022-23383: Critical severity YzmCMS YzmCMS vulnerability
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23383?
CVE-2022-23383 has a medium severity due to the potential for unauthorized access to user information.
How do I fix CVE-2022-23383?
To fix CVE-2022-23383, implement proper access control measures to verify user login status before allowing access to personal homepages.
What versions of YzCMS are affected by CVE-2022-23383?
CVE-2022-23383 affects YzCMS version 6.3.
What type of vulnerability is CVE-2022-23383?
CVE-2022-23383 is classified as a broken access control vulnerability.
Can CVE-2022-23383 be exploited remotely?
Yes, CVE-2022-23383 can be exploited remotely without requiring user login credentials.