{"id":"CVE-2023-46754","details":"The admin panel for Obl.ong before 1.1.2 allows authorization bypass because the email OTP feature accepts arbitrary numerical values.","modified":"2026-08-27T03:57:01.713454620Z","published":"2023-10-26T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/46xxx/CVE-2023-46754.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://github.com/obl-ong/admin/releases/tag/v1.1.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/46xxx/CVE-2023-46754.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-46754"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/obl-ong/panel","events":[{"introduced":"0"},{"fixed":"a0dd15f11329737c238bc7cbb0ad13c35c9272e3"}],"database_specific":{"extracted_events":[{"introduced":"Obl.ong"},{"fixed":"1.1.2"},{"introduced":"0"}],"source":["DESCRIPTION","CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:obl.ong:admin:*:*:*:*:*:*:*:*"}}],"versions":["v1.1.1","v1.1.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-46754.json"}}],"schema_version":"1.9.0"}