Security Advisory

CVE-2018-8715

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-03-14 20:00:00
Last updated 2024-08-05 07:02:25
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.