← Back to CVE List

CVE-2020-21991

Published: 2021-04-28T14:15Z
Last Modified: 2024-11-21T05:12Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt