Exploits / Vulnerability Discovered : 2021-11-11 |
Type : webapps |
Platform : multiple
This exploit / vulnerability Formalms 2.4.4 authentication bypass is for educational purposes only and if it is used you will do on your own risk!
# Info: An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.
The following exploit generates two URLs with empty and fixed value of the "secret". In order to achieve a successful exploitation the "Enable SSO with a third party software through a token" setting needs to be enabled