CVE-2018-8715
15.03.2018, 01:29
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.Enginsight
Vendor | Product | Version |
---|---|---|
embedthis | appweb | 𝑥 ≤ 7.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References