GHSA-pvrf-wj35-pxjxCriticalCVSS 9.8

An unauthenticated remote attacker can exploit an authentication bypass in the _account_log...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

🔗 References (5)