AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T14:30:33.637Z

Reserved: 2020-08-13T00:00:00

Link: CVE-2020-21991

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-28T14:15:07.577

Modified: 2024-11-21T05:12:58.763

Link: CVE-2020-21991

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.