What the vulnerability does
01Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in wovax Wovax IDX wovax-idx allows Authentication Bypass.This issue affects Wovax IDX: from n/a through <= 1.2.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Authentication Bypass Using an Alternate Path or Channel vulnerability in wovax Wovax IDX wovax-idx allows Authentication Bypass.This issue affects Wovax IDX: from n/a through <= 1.2.2.
Explanation of Vulnerability in Simple Terms
Wovax IDX versions 1.2.2 and earlier contain an authentication bypass vulnerability. An attacker with low-level user privileges can read, modify, or delete sensitive data and disrupt service availability. The vulnerability requires network access and valid user credentials but no additional user interaction. Organizations running affected versions should update immediately.
What an attacker can do
Read, modify, or delete sensitive data; disrupt service availability.
Potential impact on your site
Unauthorized data access, modification, or deletion; potential service downtime.
Conditions required to exploit
Valid low-level user account on the system; network access.
Key dates
External resources
Related vulnerabilities