What the vulnerability does
01Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authentication Bypass.This issue affects Token Login: from n/a through <= 1.0.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authentication Bypass.This issue affects Token Login: from n/a through <= 1.0.3.
Explanation of Vulnerability in Simple Terms
Token Login versions 1.0.3 and earlier contain an authentication bypass vulnerability. An attacker with low-level user privileges can bypass authentication mechanisms to gain unauthorized access to sensitive functionality. This allows reading, modifying, or deleting data without proper authorization. Sites running affected versions should update immediately.
What an attacker can do
Read, modify, or delete sensitive data by bypassing authentication checks.
Potential impact on your site
Unauthorized users with basic accounts can access admin functions and modify or delete site data.
Conditions required to exploit
Attacker needs a low-privilege user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities