CVE-2019-16766 Information
Feb 14, 2021
cve
Description
When using wagtail-2fa before 1.3.0 if someone gains access to someone’s Wagtail login credentials they can log into the CMS and bypass the 2FA check by changing the URL. They can then add a new device and gain full access to the CMS. This problem has been patched in version 1.3.0.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://github.com/labd/wagtail-2fa/commit/13b12995d35b566df08a17257a23863ab6efb0ca https://github.com/labd/wagtail-2fa/commit/a6711b29711729005770ff481b22675b35ff5c81 https://github.com/LabD/wagtail-2fa/security/advisories/GHSA-89px-ww3j-g2mm
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: