CVE-2023-43154 is a critical authentication bypass vulnerability affecting Macrob7 Macs Framework Content Management System (CMS) version 1.1.4f. This flaw stems from a PHP type confusion issue within the "isValidLogin()" function, allowing an unauthenticated attacker to bypass login and take over administrator accounts. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been confirmed, its high severity and potential for full system control warrant immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.4fCPE matchmatch criteria | cpe:2.3:a:macs_cms_project:macs_cms:1.1.4f:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.