Loading HuntDB...

GHSA-928v-hp47-95m3

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checks if LDAP authentication is selected.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel Enterprise as an administrator by selecting LDAP authentication from a hidden HTML combo box. Successful exploitation of this vulnerability also requires the attacker to know at least one username on the device, but any password will authenticate successfully.

Related CVEs

Key Information

GHSA ID
GHSA-928v-hp47-95m3
Published
August 14, 2023 6:30 AM
Last Modified
April 4, 2024 6:54 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.