Passwork before 6.2.0 allows remote authenticated users to bypass 2FA by sending all one million of the possible 6-digit codes.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://passwork.ru/ | product |
https://acribia.ru/articles/2fa_bypass_passwork | third party advisory exploit |