Описание
CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.
EPSS
Процентиль: 37%
0.00435
Низкий
7.2 High
CVSS3
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 7.2
github
13 дней назад
CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.
EPSS
Процентиль: 37%
0.00435
Низкий
7.2 High
CVSS3
Дефекты
CWE-287