PT-2024-32806 · Unknown · Lif Authentication Server

Superior126

·

Published

2024-10-04

·

Updated

2024-11-13

·

CVE-2024-47768

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lif Authentication Server versions prior to 1.7.3
Description The issue is related to the account recovery system of the Lif Authentication Server, where there is no check to ensure the user has received the recovery email and entered the correct code. An attacker who knows the target's email can supply the email and prompt the server to update the password without needing the code.
Recommendations For versions prior to 1.7.3, update to version 1.7.3 to resolve the issue. As a temporary workaround, consider restricting access to the account recovery system until the patch is applied.

Exploit

Fix

Improper Authentication

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-47768
GHSA-HMV6-8FG8-7M6F

Affected Products

Lif Authentication Server