What the vulnerability does
01Description
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
Explanation of Vulnerability in Simple Terms
The miniOrange OTP Verification plugin through version 5.5.1 uses a weak password recovery mechanism that allows attackers to bypass authentication without credentials or user interaction. An attacker can gain full control of the site, including reading and modifying all data and disrupting service. This is a critical vulnerability affecting all installations.
What an attacker can do
Bypass authentication and gain full control of the site without needing valid credentials.
Potential impact on your site
Complete compromise: attackers can read all data, modify content, create admin accounts, and take the site offline.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities