PT-2024-37544 · WordPress · Mstore Api
Truoc Phan
·
Published
2024-07-12
·
Updated
2024-07-12
·
CVE-2024-6328
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress versions up to, and including, 4.14.7
Description
The issue is due to insufficient verification on the
phone parameter of the firebase sms login and firebase sms login v2 functions. This allows unauthenticated attackers to log in as any existing user, such as an administrator, if they have access to the email address or phone number. Additionally, if a new email address is supplied, a new user account is created with the default role, even if registration is disabled.Recommendations
For versions up to, and including, 4.14.7, update to a version later than 4.14.7 to resolve the issue. As a temporary workaround, consider disabling the
firebase sms login and firebase sms login v2 functions until a patch is available. Restrict access to the phone parameter to minimize the risk of exploitation.Fix
Authentication Bypass Using an Alternate Path or Channel
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mstore Api