Vulnerabilities (CVE)

Filtered by vendor Scratchverifier
Filtered by product Scratchverifier
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-26236 1 Scratchverifier 1 Scratchverifier 2024-11-21 5.1 MEDIUM 7.5 HIGH
In ScratchVerifier before commit a603769, an attacker can hijack the verification process to log into someone else's account on any site that uses ScratchVerifier for logins. A possible exploitation would follow these steps: 1. User starts login process. 2. Attacker attempts login for user, and is given the same verification code. 3. User comments code as part of their normal login. 4. Before user can, attacker completes the login process now that the code is commented. 5. User gets a failed log ...

Show More