Описание
The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email
EPSS
Процентиль: 24%
0.00315
Низкий
9.1 Critical
CVSS3
Дефекты
Связанные уязвимости
CVSS3: 9.1
github
5 месяцев назад
The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email
EPSS
Процентиль: 24%
0.00315
Низкий
9.1 Critical
CVSS3