Vulnerabilities > Labdigital

DATE CVE VULNERABILITY TITLE RISK
2020-03-13 CVE-2020-5240 Incorrect Authorization vulnerability in Labdigital Wagtail-2Fa
In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path.
network
low complexity
labdigital CWE-863
8.5
2019-11-29 CVE-2019-16766 Unspecified vulnerability in Labdigital Wagtail-2Fa
When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into the CMS and bypass the 2FA check by changing the URL.
network
low complexity
labdigital
8.8