Security Features in WPS Hide Login - #VU24678

 

Security Features in WPS Hide Login - #VU24678

Published: January 27, 2020


Vulnerability identifier: #VU24678
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to find and access the secret login page.

The vulnerability exists in the "plugins_loaded" function due to some REQUEST_URI occurrences aren’t decoded using the "rawurldecode" function. A remote attack can encode substrings in the URL in order to evade the detection and gain access to the hidden login page.


Affected software

WPS Hide Login

Remediation

Install updates from vendor's website.

WPS Hide Login - update to 1.5.5

External References

Related Security Bulletins