
Vulnerability Research
Product: Webasyst Framework
Affected Version: ≤ 4.0.3
Severity: High (CVSS 3.1: 8.0)
Webasyst Framework through 4.0.3 contains an OAuth 2.0 implementation flaw that allows a remote, unauthenticated attacker to intercept authorization credentials issued during the OAuth flow, without requiring the victim to do anything beyond normal authorization approval. Due to improper validation, an attacker can obtain a permanent API access token and gain full, unrestricted API access to the victim's entire Webasyst account.