---
id: CVE-2022-23383
title: YzmCMS v6.3 is affected by broken access control
summary: >-
  YzmCMS v6.3 is affected by broken access control. Without login, unauthorized
  access to the user's personal home page can be realized. It is necessary to
  judge the user's login status before accessing the personal home page, but the
  vuln…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-287
vendor: yzmcms
product: yzmcms
affected:
  - yzmcms = 6.3
published: '2022-03-10'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-23383'
references:
  - url: 'https://down.chinaz.com/soft/37810.htm'
    label: cve@mitre.org
  - url: 'https://www.cnvd.org.cn/user/myreport/6499961'
    label: cve@mitre.org
  - url: 'http://yzmcms.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://down.chinaz.com/soft/37810.htm'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.cnvd.org.cn/user/myreport/6499961'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01202
epssPercentile: 0.66921
ingestedAt: '2026-07-06T17:03:23.939Z'
---

## Overview

YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because real authentication is not carried out.

## Affected

- `yzmcms = 6.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
