YOURLS through 1.7.3 is affected by a type juggling vulnerability in the API component that can result in login bypass.
https://github.com/YOURLS/YOURLS/releases/tag/1.7.4 https://github.com/YOURLS/YOURLS/pull/2542
If you have any questions or comments about this advisory: * Open an issue in YOURLS repository
{
"github_reviewed": true,
"severity": "CRITICAL",
"cwe_ids": [
"CWE-843"
],
"nvd_published_at": null,
"github_reviewed_at": "2020-06-16T21:57:30Z"
}