The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.3.7. This is due to the verify_otp_forgot_password() and update_password() functions not having enough controls to prevent a successful brute force attack of the OTP to change a password, or verify that a password reset request came from an authorized user. This makes it possible for unauthenticated attackers to generate and brute force an OTP that makes it possible to change any users passwords, including an administrator.
History

Tue, 05 Nov 2024 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:appcheap:app_builder:*:*:*:*:*:wordpress:*:*

Fri, 25 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Appcheap
Appcheap app Builder
CPEs cpe:2.3:a:appcheap:app_builder:-:*:*:*:*:wordpress:*:*
Vendors & Products Appcheap
Appcheap app Builder
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 25 Oct 2024 07:00:00 +0000

Type Values Removed Values Added
Description The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.3.7. This is due to the verify_otp_forgot_password() and update_password() functions not having enough controls to prevent a successful brute force attack of the OTP to change a password, or verify that a password reset request came from an authorized user. This makes it possible for unauthenticated attackers to generate and brute force an OTP that makes it possible to change any users passwords, including an administrator.
Title App Builder – Create Native Android & iOS Apps On The Flight <= 5.3.7 - Privilege Escalation and Account Takeover via Weak OTP
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-10-25T06:51:23.501Z

Updated: 2024-10-25T14:13:47.782Z

Reserved: 2024-09-27T17:19:49.916Z

Link: CVE-2024-9302

cve-icon Vulnrichment

Updated: 2024-10-25T14:13:43.198Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-25T07:15:05.617

Modified: 2024-11-05T17:39:17.120

Link: CVE-2024-9302

cve-icon Redhat

No data.