1 results (0.002 seconds)
CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 2
CVE-2022-0992 – SiteGround Security <= 1.2.5 - Authentication Bypass via 2FA Setup
https://notcve.org/view.php?id=CVE-2022-0992
06 Apr 2022 — The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allows unauthenticated and unauthorized users to configure 2FA for pending accounts. Upon successful configuration, the attacker is logged in as that user without access to a username/password pair which is the expected first form of authentication. This affects versions up to, and including, 1.... • https://packetstorm.news/files/id/166642 • CWE-288: Authentication Bypass Using an Alternate Path or Channel CWE-306: Missing Authentication for Critical Function •