CVE Published: 20/12/2023 |
CVE Updated: 16/09/2024 |
CVE Year: 2023 Source: INCIBE |
Vendor: Amazing Little poll |
Product: Amazing Little poll Status : PUBLISHED
CVE-2023-6768 Description
Authentication bypass vulnerability in Amazing Little Poll affecting versions 1.3 and 1.4. This vulnerability could allow an unauthenticated user to access the admin panel without providing any credentials by simply accessing the "lp_admin.php?adminstep=" parameter.
Metrics
CVSS Version: 3.1 |
Base Score: 9.4 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L