CVE-2018-8715

Publication date

2018-03-14 20:00:00

Family

mitre

State

PUBLISHED

Description

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.