Lucene search

K
wpvulndbPhilip ÅkessonWPVDB-ID:C0433E94-3BCC-438A-9369-2607AEC8B067
HistoryOct 02, 2020 - 12:00 a.m.

WordPress + Microsoft Office 365 < 11.7 - JWT Signature Verification Bypass

2020-10-0200:00:00
Philip Åkesson
wpscan.com
11
wordpress microsoft office 365 jwt signatures verification bypass authentication authorization_attackers tokens forged_connections_security vulnerability .

EPSS

0.002

Percentile

53.4%

The plugin does not correctly verify JWT signatures, allowing attackers to forge tokens and bypass authentication and authorisation checks.

EPSS

0.002

Percentile

53.4%

Related for WPVDB-ID:C0433E94-3BCC-438A-9369-2607AEC8B067