9.8
CVE-2023-6768
- EPSS 0.07%
- Veröffentlicht 20.12.2023 10:15:07
- Zuletzt bearbeitet 21.11.2024 08:44:31
- Quelle cve-coordination@incibe.es
- CVE-Watchlists
- Unerledigt
Authentication bypass vulnerability in Amazing Little Poll affecting versions 1.3 and 1.4. This vulnerability could allow an unauthenticated user to access the admin panel without providing any credentials by simply accessing the "lp_admin.php?adminstep=" parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mr-corner ≫ Amazing Little Poll Version1.3
Mr-corner ≫ Amazing Little Poll Version1.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.209 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| cve-coordination@incibe.es | 9.4 | 3.9 | 5.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.