Vulnerability Description
When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into the CMS and bypass the 2FA check by changing the URL. They can then add a new device and gain full access to the CMS. This problem has been patched in version 1.3.0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Labdigital | Wagtail-2Fa | < 1.3.0 |
Related Weaknesses (CWE)
References
- https://github.com/LabD/wagtail-2fa/security/advisories/GHSA-89px-ww3j-g2mmThird Party Advisory
- https://github.com/labd/wagtail-2fa/commit/13b12995d35b566df08a17257a23863ab6efbPatchThird Party Advisory
- https://github.com/labd/wagtail-2fa/commit/a6711b29711729005770ff481b22675b35ff5PatchThird Party Advisory
- https://github.com/LabD/wagtail-2fa/security/advisories/GHSA-89px-ww3j-g2mmThird Party Advisory
- https://github.com/labd/wagtail-2fa/commit/13b12995d35b566df08a17257a23863ab6efbPatchThird Party Advisory
- https://github.com/labd/wagtail-2fa/commit/a6711b29711729005770ff481b22675b35ff5PatchThird Party Advisory
FAQ
What is CVE-2019-16766?
CVE-2019-16766 is a vulnerability with a CVSS score of 8.7 (HIGH). When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into the CMS and bypass the 2FA check by changing the URL. They can then add a new dev...
How severe is CVE-2019-16766?
CVE-2019-16766 has been rated HIGH with a CVSS base score of 8.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-16766?
Check the references section above for vendor advisories and patch information. Affected products include: Labdigital Wagtail-2Fa.