Improper Authentication in Ultimate Membership Pro - #VU25010

 

Improper Authentication in Ultimate Membership Pro - #VU25010

Published: February 6, 2020


Vulnerability identifier: #VU25010
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to insufficient authentication. A remote attacker can bypass authentication process and execute arbitrary code on the target system or gain access to sensitive information.


Affected software

Ultimate Membership Pro

Remediation

Install updates from vendor's website.

Ultimate Membership Pro - update to 8.6.1

External References

Related Security Bulletins