Executive brief
Creartia's ICMS is a content management system used for digitalizing business operations. A security flaw in its login process allows unauthorized individuals to bypass security checks and gain full access to protected administrative features. This could lead to the theft of sensitive data or complete control over the website's content without needing a username or password.
Technical details
An authentication bypass vulnerability (CWE-288) exists in Creartia's ICMS (Gestión de Contenidos) due to improper handling of the login redirect process. By manipulating HTTP redirect headers, an attacker can prevent the authentication script from terminating correctly, allowing the subsequent protected code to execute. This flaw enables a remote, unauthenticated attacker to bypass the login screen and gain administrative access to the software's features. The vulnerability has been addressed by the vendor, and users are advised to update to the latest version.
Affected products
- Creartia Internet Consulting ICMS Gestión de Contenidos
Timeline
- 2026-05-18: disclosed
- 2026-05-18: advisory
- 2026-05-18: patched: Vendor released a fix; update to the latest version recommended.