Improper Authentication in Ultimate Addons for Beaver Builder - #VU23579

 

Improper Authentication in Ultimate Addons for Beaver Builder - #VU23579

Published: December 13, 2019


Vulnerability identifier: #VU23579
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to the lack of checks when logging in via Facebook or Google. A remote attacker who knows the email ID of any user can send a specially crafted request, bypass authentication process and gain unauthorized access to the application.


Affected software

Ultimate Addons for Beaver Builder

Remediation

Install updates from vendor's website.

Ultimate Addons for Beaver Builder - update to 1.24.1

External References

Related Security Bulletins