Files
CVEs-PoC/2020/CVE-2020-21991.md
T
2024-05-25 21:48:12 +02:00

928 B

CVE-2020-21991

Description

AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials.

POC

Reference

Github

No PoCs found on GitHub currently.