Embedthis.Appweb.authCondition.Authentication.Bypass

description-logoDescription

This indicates an attack attempt to exploit an Authentication Bypass vulnerability in Embedthis Appweb.
The vulnerability is caused by an insufficient authentication validation when authenticating an user. An unauthenticated attacker can exploit this with a crafted request to obtain a valid session, even an admin session.

affected-products-logoAffected Products

Embedthis HTTP library, and Appweb versions before 7.0.3

Impact logoImpact

Security Bypass: Remote attackers can bypass security features of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://www.embedthis.com/appweb/

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2024-04-17 27.770 Default_action:pass:drop
2024-04-08 27.762