CVE-2019-16766 Information

Description

When using wagtail-2fa before 1.3.0 if someone gains access to someone’s Wagtail login credentials they can log into the CMS and bypass the 2FA check by changing the URL. They can then add a new device and gain full access to the CMS. This problem has been patched in version 1.3.0.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://github.com/labd/wagtail-2fa/commit/13b12995d35b566df08a17257a23863ab6efb0ca https://github.com/labd/wagtail-2fa/commit/a6711b29711729005770ff481b22675b35ff5c81 https://github.com/LabD/wagtail-2fa/security/advisories/GHSA-89px-ww3j-g2mm

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.8

Share on: