An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://blog.hacktivesecurity.com | third party advisory |
https://formalms.org | vendor advisory |
https://blog.hacktivesecurity.com/index.php/2021/10/05/cve-2021-43136-formalms-the-evil-default-value-that-leads-to-authentication-bypass/ | third party advisory exploit |
http://packetstormsecurity.com/files/164930/FormaLMS-2.4.4-Authentication-Bypass.html | third party advisory vdb entry exploit |