Record summary

CVE-2018-8715 has a selected CVSS score of 8.1 (high); EIP currently links 1 Nuclei template.

Description

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHAppWeb - Authentication BypassCVSS 8.1

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.

Impact

Successful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to the application.

Remediation

Apply the necessary patches or updates provided by the vendor to fix the authentication bypass vulnerability in AppWeb.

WeaknessesCWE-287
Authorsmilo2012
Template tagscvecve2018appwebauth-bypassembedthisvuln
CVSS vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:embedthis:appweb:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:embedthis:appweb"

Source: ProjectDiscovery

References

4