VYPR
Unrated severityNVD Advisory· Published Oct 17, 2022· Updated May 14, 2025

CVE-2022-41471

CVE-2022-41471

Description

74cmsSE v3.12.0 allows authenticated attackers with low-level privileges to arbitrarily change the rights and credentials of the Super Administrator account.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated low-privilege users in 74cmsSE v3.12.0 can change the super administrator password via improper permission configuration.

Vulnerability

74cmsSE v3.12.0 contains an improper permission configuration vulnerability that allows authenticated users assigned a low-privilege role to modify the rights and credentials of the Super Administrator account [1]. The flaw resides in the role rights management functionality, where the system does not properly enforce access controls when editing senior administrator roles or super administrator accounts.

Exploitation

An attacker must first authenticate as a low-privilege user. To achieve this, an administrator (or an existing user with sufficient privileges) must create a role with minimal rights via System > Role Rights Management, then create a low-permission account under that role through System > Administrator List [1]. Once logged in with that low-permission account, the attacker can navigate to the administrator management interface and edit the senior administrator role or the super administrator account directly, and change the super administrator password without any additional authorization checks [1].

Impact

A successful attack results in the attacker gaining the ability to arbitrarily change the password of the Super Administrator account, effectively taking full control of the 74cmsSE installation [1]. This compromise leads to complete loss of confidentiality, integrity, and availability of the application and its data, as the attacker can then perform any administrative action.

Mitigation

As of the available references, no official patched version or security update has been released by the vendor for 74cmsSE v3.12.0 [1]. Organizations running this version should restrict access to the application to trusted users only, audit administrator account changes regularly, and consider implementing additional network-level controls such as web application firewalls (WAF) to monitor for abnormal permission changes. If no update becomes available, migrating away from this software should be evaluated.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.