ID:9472 - Exploit for Improper access control in Apache Shiro - CVE-2016-4437
Published: January 2, 2024
Apache Shiro
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code or bypass intended access restrictions.
The vulnerability exists due to improper access restrictions when a cipher key is not been configured for the "remember me" feature. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the application.