CVE-2021-45379

HIGH

Glewlwyd 2.0.0-2.6.0 - Unauthenticated Incorrect Access Control

Title source: llm
STIX 2.1

Description

Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in as another user without its password.

References (2)

Core 2
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/babelouest/glewlwyd/releases/tag/v2.6.1

Scores

CVSS v3 8.8
EPSS 0.0100
EPSS Percentile 58.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
glewlwyd_project/glewlwyd 2.0.0 - 2.6.1
Published Dec 30, 2021
Tracked Since Feb 18, 2026