PT-2026-83989 · Wallos · Wallos
CVE-2026-54599
·
Published
2026-08-31
·
Updated
2026-08-31
CVSS v4.0
7.5
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Wallos versions prior to 4.9.4
Description
An issue exists where
login.php generates an OIDC state nonce stored in $ SESSION['oidc state'], but checksession.php dispatches the OIDC callback without comparing the incoming state against the session value. This allows an attacker to trick a victim into visiting a crafted URL, leading the application to exchange the attacker's authorization code and log the victim into the attacker's account.Recommendations
Update to version 4.9.4.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wallos