Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-43154

EPSS 0.41% · P62
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-43154

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Macrob7 Macs Framework Cms 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Macrob7 Macs Framework Cms是Macdonald Terrence Robinson个人开发者的一个开源的 Cms 框架。 Macrob7 Macs Framework Cms v1.1.4f CMS存在安全漏洞,该漏洞源于isValidLogin()函数存在类型混淆漏洞。攻击者可利用该漏洞绕过身份验证并接管管理员帐户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2023-43154

#POC DescriptionSource LinkShenlong Link
1PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.https://github.com/ally-petitt/CVE-2023-43154-PoCPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-43154

登录查看更多情报信息。

Same Patch Batch · n/a · 2023-09-26 · 24 CVEs total

CVE-2023-340436.7 MEDIUMVMware Aria Operations 安全漏洞
CVE-2023-43331Small CRM 跨站脚本漏洞
CVE-2021-38243XunRuiCMS 安全漏洞
CVE-2023-35793Cassia Networks Access Controller 跨站请求伪造漏洞
CVE-2023-41904Zoho ManageEngine ADManager Plus 授权问题漏洞
CVE-2023-43187NodeBB 安全漏洞
CVE-2023-43216SeaCMS 安全漏洞
CVE-2023-43222SeaCMS 安全漏洞
CVE-2023-43232DedeBIZ 跨站脚本漏洞
CVE-2023-43234DedeBIZ 安全漏洞
CVE-2023-43263Froala Editor 跨站脚本漏洞
CVE-2023-43291emlog 代码问题漏洞
CVE-2023-44216Imagination 安全漏洞
CVE-2023-43381Tianchoy Blog SQL注入漏洞
CVE-2023-43856Dreamer CMS 安全漏洞
CVE-2023-43857Dreamer CMS 跨站脚本漏洞
CVE-2023-44042Blackcat Cms 跨站脚本漏洞
CVE-2023-44043Blackcat Cms 跨站脚本漏洞
CVE-2023-44044Super Store Finder SQL注入漏洞
CVE-2023-44169SeaCMS 安全漏洞

Showing top 20 of 24 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2023-43154

No comments yet


Leave a comment