Vulnerabilities > Labdigital > Wagtail 2FA > 1.3.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-03-13 | CVE-2020-5240 | Incorrect Authorization vulnerability in Labdigital Wagtail-2Fa In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. | 8.5 |