CVE-2018-8715
AppWeb - Authentication Bypass
Record summary
CVE-2018-8715 has a selected CVSS score of 8.1 (high); EIP currently links 1 Nuclei template.
Description
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHAppWeb - Authentication BypassCVSS 8.1
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.
Impact
Successful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to the application.
Remediation
Apply the necessary patches or updates provided by the vendor to fix the authentication bypass vulnerability in AppWeb.
Source: ProjectDiscovery