Описание
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.
Ссылки
- ExploitThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.0.2 (включая)
cpe:2.3:a:embedthis:appweb:*:*:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.92326
Критический
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 8.1
github
больше 3 лет назад
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.
EPSS
Процентиль: 100%
0.92326
Критический
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-287