CyberRota Analysis
AI-GeneratedFeehi CMS version 2.1.1 is susceptible to incorrect access control, allowing low-privilege backend administrators with update permissions to change the password of the super administrator account without needing the old password. This vulnerability could lead to unauthorized access and control over the entire CMS, posing a significant security risk. Organizations using this CMS should prioritize remediation to prevent potential exploitation by malicious actors.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can change the password of the built-in super administrator account. The server does not enforce protection for this account, and the update scenario does not require the old password.