Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8j44-5653-q846

Опубликовано: 29 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled seed to generate a matching one-time password and bypass the second authentication factor, potentially enabling unauthorised access to administrator accounts.

A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled seed to generate a matching one-time password and bypass the second authentication factor, potentially enabling unauthorised access to administrator accounts.

EPSS

Процентиль: 2%
0.00117
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 4.8
nvd
14 дней назад

A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled seed to generate a matching one-time password and bypass the second authentication factor, potentially enabling unauthorised access to administrator accounts.

EPSS

Процентиль: 2%
0.00117
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-347