CVE Vulnerabilities

CVE-2023-6768

Improper Authentication

Published: Dec 20, 2023 | Modified: Dec 22, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Authentication bypass vulnerability in Amazing Little Poll affecting versions 1.3 and 1.4. This vulnerability could allow an unauthenticated user to access the admin panel without providing any credentials by simply accessing the lp_admin.php?adminstep= parameter.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Amazing_little_poll Mr-corner 1.3 (including) 1.3 (including)
Amazing_little_poll Mr-corner 1.4 (including) 1.4 (including)

Potential Mitigations

References