GHSA-g8pg-33v4-9r96HighCVSS 7.5Disclosed before NVD
Thelia authentication bypass vulnerability
📋 Description
An authentication bypass was identifed in thelia/thelia project for customer and admin. This vulnerability is present from version 2.0.0-beta1 and is fixed in 2.1.3 and 2.2.0-alpha1.
🎯 Affected products1
- composer/thelia/thelia:>= 2.0.0-beta1, < 2.1.3
🔗 References (6)
- https://github.com/thelia/thelia/commit/028cfcf507cd8685772e156ec0c860034d407094
- https://github.com/FriendsOfPHP/security-advisories/blob/master/thelia/thelia/2015-04-13-1.yaml
- https://web.archive.org/web/20160502224630/http://thelia.net/version-2-1-3-with-security-fix
- https://github.com/github/advisory-database/pull/8012
- https://github.com/thelia/thelia/commit/71c1cee66d8f2e515e82478f792879fa63843644
- https://github.com/advisories/GHSA-g8pg-33v4-9r96