packetstormsecurity.com
http://packetstormsecurity.com/files/164930/FormaLMS-2.4.4-Authentication-Bypass.html CVE-2021-43136
CRITICAL
FormaLMS 2.4.4 - Authentication Bypass
Record summary
CVE-2021-43136 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFormaLMS 2.4.4 - Authentication BypassExploitDB exploitby Cristian \'void\' GiustiniNot analyzed1 file
References
5blog.hacktivesecurity.com
https://blog.hacktivesecurity.com/ blog.hacktivesecurity.com
https://blog.hacktivesecurity.com/index.php/2021/10/05/cve-2021-43136-formalms-the-evil-default-value-that-leads-to-authentication-bypass formalms.org
https://formalms.org/ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-43136