Описание
Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.
Ссылки
EPSS
Процентиль: 20%
0.00274
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 9.1
github
9 дней назад
Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.
EPSS
Процентиль: 20%
0.00274
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-287