What the vulnerability does
01Description
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
Explanation of Vulnerability in Simple Terms
The OAuth Single Sign On plugin for miniOrange contains an authentication bypass vulnerability that allows attackers to spoof authentication tokens without valid credentials. An attacker can gain unauthorized access to any user account, including administrator accounts, by manipulating the OAuth authentication flow. This affects all versions up to 7.0.0 and requires no user interaction or special privileges to exploit.
What an attacker can do
Bypass authentication and log in as any user, including site administrators, without knowing their password.
Potential impact on your site
Complete compromise of site security; attackers can access all user accounts and administrative functions.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities