PT-2024-39557 · WordPress · The App Builder – Create Native Android & Ios Apps On The Flight
Wesley
·
Published
2024-10-25
·
Updated
2024-11-05
·
CVE-2024-9302
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress versions up to, and including, 5.3.7
Description
The issue is related to privilege escalation via account takeover. This is due to the
verify otp forgot password() and update password() functions not having enough controls to prevent a successful brute force attack of the OTP to change a password, or verify that a password reset request came from an authorized user. This makes it possible for unauthenticated attackers to generate and brute force an OTP that makes it possible to change any users passwords, including an administrator.Recommendations
For versions up to, and including, 5.3.7, as a temporary workaround, consider disabling the
verify otp forgot password() and update password() functions until a patch is available. Restrict access to password reset functionality to minimize the risk of exploitation. Avoid using the OTP mechanism in the affected plugin until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The App Builder – Create Native Android & Ios Apps On The Flight