All CosmicBytez Labs articles tagged #CWE-287, across news, security advisories, how-to guides, and projects.
Maximum severity CVE in Priority ERP's portal addon allows unauthenticated remote attackers to bypass authentication entirely. Patch immediately.
A critical improper authentication vulnerability in WP Events Manager for WordPress allows unauthenticated attackers to register for paid events without payment by manipulating the quantity parameter. Fixed in version 2.2.5.
The Happy Coders OTP Login for WooCommerce plugin before 2.8 allows unauthenticated attackers to bypass OTP verification and log in as any WordPress user,...
A CVSS 9.8 authentication bypass in Nefteprodukttekhnika's BUK TS-G Gas Station Automation System allows any unauthenticated attacker to gain full...
A critical CVSS 10.0 authentication bypass in Traefik's ForwardAuth middleware allows attackers to circumvent authentication when the proxy is deployed...
KodExplorer versions up to 4.52 contain an improper authentication flaw in the fileGet endpoint that allows remote attackers to access files without valid...