CVE-2023-6768

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
20/12/2023
Last modified:
22/12/2023

Description

Authentication bypass vulnerability in Amazing Little Poll affecting versions 1.3 and 1.4. This vulnerability could allow an unauthenticated user to access the admin panel without providing any credentials by simply accessing the "lp_admin.php?adminstep=" parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mr-corner:amazing_little_poll:1.3:*:*:*:*:*:*:*
cpe:2.3:a:mr-corner:amazing_little_poll:1.4:*:*:*:*:*:*:*