← back
CVE-2023-6768

Authentication bypass vulnerability in Amazing Little Poll

CVSS 9.4 CRITICALEPSS 1.0%CWE-287
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.4EPSS 1.0%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
20 Dec 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Authentication bypass vulnerability in Amazing Little Poll affecting versions 1.3 and 1.4. This vulnerability could allow an unauthenticated user to access the admin panel without providing any credentials by simply accessing the "lp_admin.php?adminstep=" parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →