Description
The admin panel for Obl.ong before 1.1.2 allows authorization bypass because the email OTP feature accepts arbitrary numerical values.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-50921 | The admin panel for Obl.ong before 1.1.2 allows authorization bypass because the email OTP feature accepts arbitrary numerical values. |
References
| Link | Providers |
|---|---|
| https://github.com/obl-ong/admin/releases/tag/v1.1.2 |
|
History
Tue, 29 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-29T20:06:55.176Z
Reserved: 2023-10-26T00:00:00.000Z
Link: CVE-2023-46754
Updated: 2024-08-02T20:53:21.835Z
Status : Modified
Published: 2023-10-26T05:15:26.173
Modified: 2024-11-21T08:29:14.170
Link: CVE-2023-46754
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD