Vulnerabilities > Labdigital > Wagtail 2FA > 1.3.0

DATE CVE VULNERABILITY TITLE RISK
2020-03-13 CVE-2020-5240 Incorrect Authorization vulnerability in Labdigital Wagtail-2Fa
In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path.
network
low complexity
labdigital CWE-863
5.5