CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2022-23383

Critical · CVSS 9.1

YzmCMS — Broken Access Control / Authentication Bypass (CWE-287)

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-287

Description

YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.

Search profile — drives PoC discovery

Symbols member/index/indexuser home pagelogin status checkpersonal home pagemember moduleisloginchecklogin
Keywords CVE-2022-23383YzmCMSYzmCMS v6.3broken access controlunauthorized accessauthentication bypasspersonal home pageunauthenticatedmember profile
Versions: v6.3

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z