VendorsLinOTPvirtual_applianceany version
Vulnerabilities

LinOTP Virtual Appliance any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2023-49706
Defective request context handling in Self Service in LinOTP 3.x before 3.2.5 allows remote unauthenticated attackers to escalate privileges, thereby allowing them to act as and with the permissions of another user. Attackers must generate repeated API requests to trigger a race condition with concurrent user activity in the self-service portal.
Published 2023-12-19 · Modified
6.8EPSS 0.006