Описание
The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to the extensions MFA provider.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.7 (исключая)
Одно из
cpe:2.3:a:mrsilaz:mfa_mail:*:*:*:*:*:typo3:*:*
cpe:2.3:a:mrsilaz:mfa_mail:2.0.0:*:*:*:*:typo3:*:*
EPSS
Процентиль: 17%
0.00256
Низкий
8.8 High
CVSS3
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 8.8
github
5 месяцев назад
Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)
EPSS
Процентиль: 17%
0.00256
Низкий
8.8 High
CVSS3
Дефекты
CWE-639