Vulnerabilities > Redwoodhq

DATE CVE VULNERABILITY TITLE RISK
2019-06-19 CVE-2019-12890 Missing Authentication for Critical Function vulnerability in Redwoodhq 2.0/2.5.5
RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automationframework users insert_one call.
network
low complexity
redwoodhq CWE-306
7.5