Vulnerability CVE-2021-24148


Published: 2021-03-18

Description:
A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.

Type:

CWE-287

(Improper Authentication)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Inspireui -> Mstore api 

 References:
https://wpscan.com/vulnerability/bf5ddc43-974d-41fa-8276-c1a27d3cc882

Copyright 2024, cxsecurity.com

 

Back to Top