Home
MEDIUM: 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:NDefault status
unaffected
Any version
affected
Description
The HttpAuth plugin in pGina.Fork through 3.9.9.12 allows authentication bypass when an adversary controls DNS resolution for pginaloginserver.
Problem types
CWE-290 Authentication Bypass by Spoofing
Product status
Any version
References
github.com/...ns/CVE/blob/main/pGina.Fork/3.9.9.12/README.md
github.com/...b364bbad/Plugins/HttpAuth/HttpAuth/Settings.cs