CVE-2022-23383
Critical · CVSS 9.1YzmCMS — Broken Access Control / Authentication Bypass (CWE-287)
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-287
Description
YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.
Search profile — drives PoC discovery
Symbols member/index/indexuser home pagelogin status checkpersonal home pagemember moduleisloginchecklogin
Keywords CVE-2022-23383YzmCMSYzmCMS v6.3broken access controlunauthorized accessauthentication bypasspersonal home pageunauthenticatedmember profile
Versions: v6.3
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z