Vulnerability Description
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Formalms | Formalms | <= 2.4.4 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/164930/FormaLMS-2.4.4-Authentication-BypassExploitThird Party AdvisoryVDB Entry
- https://blog.hacktivesecurity.comThird Party Advisory
- https://blog.hacktivesecurity.com/index.php/2021/10/05/cve-2021-43136-formalms-tExploitThird Party Advisory
- https://formalms.orgVendor Advisory
- http://packetstormsecurity.com/files/164930/FormaLMS-2.4.4-Authentication-BypassExploitThird Party AdvisoryVDB Entry
- https://blog.hacktivesecurity.comThird Party Advisory
- https://blog.hacktivesecurity.com/index.php/2021/10/05/cve-2021-43136-formalms-tExploitThird Party Advisory
- https://formalms.orgVendor Advisory
FAQ
What is CVE-2021-43136?
CVE-2021-43136 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.
How severe is CVE-2021-43136?
CVE-2021-43136 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-43136?
Check the references section above for vendor advisories and patch information. Affected products include: Formalms Formalms.