vendor:
FormaLMS
by:
Cristian 'void' Giustini
9.8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: FormaLMS
Affected Version From: <= 2.4.4
Affected Version To: <= 2.4.4
Patch Exists: NO
Related CWE: CVE-2021-43136
CPE: a:formalms:formalms:2.4.4
Platforms Tested: Linux
2021
FormaLMS 2.4.4 – Authentication Bypass
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platform.
Mitigation:
Apply the vendor's patch or update to a fixed version of FormaLMS. Disable the 'Enable SSO with a third party software through a token' setting if not required.