What the vulnerability does
01Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Deryck User Toolkit user-toolkit allows Authentication Bypass.This issue affects User Toolkit: from n/a through <= 1.2.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Authentication Bypass Using an Alternate Path or Channel vulnerability in Deryck User Toolkit user-toolkit allows Authentication Bypass.This issue affects User Toolkit: from n/a through <= 1.2.3.
Explanation of Vulnerability in Simple Terms
User Toolkit versions 1.2.3 and earlier contain an authentication bypass vulnerability. An attacker can gain unauthorized access to the application without valid credentials. The vulnerability affects confidentiality, integrity, and availability of the system. Update to a version newer than 1.2.3 immediately.
What an attacker can do
Gain full unauthorized access to the application without credentials.
Potential impact on your site
Complete compromise of User Toolkit data and functionality; attackers can read, modify, or delete information.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities