CleverStupidDog yf-exam v 1.8.0 is vulnerable to...
High severity
Unreviewed
Published
Mar 4, 2023
to the GitHub Advisory Database
•
Updated Mar 18, 2023
Description
Published by the National Vulnerability Database
Mar 3, 2023
Published to the GitHub Advisory Database
Mar 4, 2023
Last updated
Mar 18, 2023
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored key uses username format characters. Any user who logged in within 24 hours. A token can be forged with his username to bypass authentication.
References