What the vulnerability does
01Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authentication Bypass.This issue affects MaanStore API: from n/a through <= 1.0.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authentication Bypass.This issue affects MaanStore API: from n/a through <= 1.0.1.
Explanation of Vulnerability in Simple Terms
MaanStore API versions 1.0.1 and earlier contain an authentication bypass vulnerability. An attacker can gain unauthorized access to the API without valid credentials, potentially reading, modifying, or deleting data. No user interaction or special privileges are required. Organizations using affected versions should update immediately.
What an attacker can do
Gain unauthorized access to the API and read, modify, or delete data without authentication.
Potential impact on your site
Attackers can access, modify, or delete sensitive data in your MaanStore installation without logging in.
Conditions required to exploit
Network access to the MaanStore API; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities