← Back

Linotp

linotp

1 CVE • 2 products

Products (2)

Click to collapse
Toggle
Linotp
linotp

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Linotp
2Linotp
Virtual Appliance
Jun 17, 2026
Dec 19, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Defective request context handling in Self Service in LinOTP 3.x before 3.2.5 allows remote unauthenticated attackers to escalate privileges, thereby allowing them to act as and with the permissions of another user. Atta...Show more
Defective request context handling in Self Service in LinOTP 3.x before 3.2.5 allows remote unauthenticated attackers to escalate privileges, thereby allowing them to act as and with the permissions of another user. Attackers must generate repeated API requests to trigger a race condition with concurrent user activity in the self-service portal.Show less