Loading
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.
Use CWE-287, Embedthis vendor hub and Appweb product page to widen CVE-2018-8715 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-33254, CVE-2020-15689 and CVE-2018-15505 for nearby disclosures in the same product family.