An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnerability to access API without any token.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54898 | An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnerability to access API without any token. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 21 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 | |
| Metrics |
cvssV3_1
|
Thu, 21 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnerability to access API without any token. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-21T18:56:26.719Z
Reserved: 2024-10-28T00:00:00.000Z
Link: CVE-2024-50641
Updated: 2025-08-21T18:55:50.209Z
Status : Awaiting Analysis
Published: 2025-08-21T18:15:33.713
Modified: 2025-08-22T18:08:51.663
Link: CVE-2024-50641
No data.
OpenCVE Enrichment
No data.
EUVD