Skip to content

WI1D-41/IDOR-in-MFASOFT-Secure-Authentication-Server

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 

Repository files navigation

Insecure access to user tokens data in MFASOFT Secure Authentication Server 1.8.x through 1.9.x before 1.9.040924

Vulnerability, allows you to view data about user tokens without authentication (IDOR) on the endpoint “/api-selfportal/get-info-token-properties” by brute-forcing the “serial” parameter. The search was carried out using the code GA0000NUM

About

insecure access to user tokens data

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published