MStore API <= 3.1.9 - Authentication Bypass
2021-02-02 00:00
Vincent DatrierStrategic Overview
StatusPatched in 3.2.0
Affected PluginMStore API – Create Native Android & iOS Apps On The Cloud
Affected Version
<= 3.1.9CVSS9.8Critical
CVE
CVE-2021-24148Vulnerability Overview
A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.
Technical Analysis
REMEDIATION: Update to version 3.2.0, or a newer patched version --- IDENTIFIER: CWE-288 (Authentication Bypass Using an Alternate Path or Channel) The product requires authentication, but the product has an alternate path or channel that does not require authentication.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C