Vulnerability CVE-2019-16766


Published: 2019-11-29   Modified: 2019-12-04

Description:
When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into the CMS and bypass the 2FA check by changing the URL. They can then add a new device and gain full access to the CMS. This problem has been patched in version 1.3.0.

Type:

CWE-522

(Insufficiently Protected Credentials)

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Labdigital -> Wagtail-2fa 

 References:
https://github.com/labd/wagtail-2fa/commit/13b12995d35b566df08a17257a23863ab6efb0ca
https://github.com/labd/wagtail-2fa/commit/a6711b29711729005770ff481b22675b35ff5c81
https://github.com/LabD/wagtail-2fa/security/advisories/GHSA-89px-ww3j-g2mm

Copyright 2024, cxsecurity.com

 

Back to Top