Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
google authenticator vulnerabilities and exploits
(subscribe to this query)
169
VMScore
CVE-2012-6140
pam_google_authenticator.c in the PAM module in Google Authenticator prior to 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem operations, a different v...
Google Authenticator 0.86
Google Authenticator
Google Authenticator 0.87
445
VMScore
CVE-2013-4177
The Google Authenticator login module 6.x-1.x prior to 6.x-1.2 and 7.x-1.x prior to 7.x-1.4 for Drupal does not properly identify user account names, which might allow remote malicious users to bypass the two-factor authentication requirement via unspecified vectors.
Google Authenticator Login Project Ga Login 6.x-1.0
Google Authenticator Login Project Ga Login 6.x-1.1
Google Authenticator Login Project Ga Login 6.x-1.x
Google Authenticator Login Project Ga Login 7.x-1.0
Google Authenticator Login Project Ga Login 7.x-1.1
Google Authenticator Login Project Ga Login 7.x-1.2
Google Authenticator Login Project Ga Login 7.x-1.3
445
VMScore
CVE-2013-4178
The Google Authenticator login module 6.x-1.x prior to 6.x-1.2 and 7.x-1.x prior to 7.x-1.4 for Drupal allows remote malicious users to obtain access by replaying the username, password, and one-time password (OTP).
Google Authenticator Login Project Ga Login 6.x-1.0
Google Authenticator Login Project Ga Login 6.x-1.1
Google Authenticator Login Project Ga Login 6.x-1.x
Google Authenticator Login Project Ga Login 7.x-1.0
Google Authenticator Login Project Ga Login 7.x-1.1
Google Authenticator Login Project Ga Login 7.x-1.2
Google Authenticator Login Project Ga Login 7.x-1.3
605
VMScore
CVE-2013-0258
The Google Authenticator login (ga_login) module 7.x prior to 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote malicious users to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.
Google Authenticator Login Project Ga Login 7.x-1.0
Google Authenticator Login Project Ga Login 7.x-1.1
Google Authenticator Login Project Ga Login 7.x-1.2
NA
CVE-2022-42461
Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress.
Miniorange Google Authenticator
516
VMScore
CVE-2022-0229
The miniOrange's Google Authenticator WordPress plugin prior to 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary o...
Miniorange Google Authenticator
383
VMScore
CVE-2022-0875
The Google Authenticator WordPress plugin prior to 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing malicious users to make a logged in admin change them and perform Cross-Site Scripting attacks
Miniorange Google Authenticator
NA
CVE-2022-44589
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in miniOrange miniOrange's Google Authenticator – WordPress Two Factor Authentication – 2FA , Two Factor, OTP SMS and Email | Passwordless login.This issue affects miniOrange's Google A...
Miniorange Google Authenticator
312
VMScore
CVE-2022-1321
The miniOrange's Google Authenticator WordPress plugin prior to 5.5.6 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html i...
Miniorange Google Authenticator
NA
CVE-2022-4943
The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated malicious users to change the ...
Miniorange Google Authenticator
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5841
file upload
man-in-the-middle
arbitrary
CVE-2024-27801
CVE-2024-28020
CVE-2024-30080
CVE-2024-30069
CVE-2024-5843
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »