ally-petitt/CVE-2023-43154-PoC

ally-petitt/CVE-2023-43154-PoC

Releases0
PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account.