Описание
The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to the extensions MFA provider.
EPSS
Процентиль: 17%
0.00055
Низкий
Дефекты
CWE-639
Связанные уязвимости
github
24 дня назад
Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)
EPSS
Процентиль: 17%
0.00055
Низкий
Дефекты
CWE-639