{"id":"GHSA-g8pg-33v4-9r96","aliases":[],"url":"https://o3.security/vulnerability/GHSA-g8pg-33v4-9r96","summary":"Thelia authentication bypass vulnerability","details":"An authentication bypass was identifed in thelia/thelia project for customer and admin. This vulnerability is present from version 2.0.0-beta1 and is fixed in 2.1.3 and 2.2.0-alpha1.","published":"2024-05-30T13:26:47Z","modified":"2026-07-17T18:30:27.884445483Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"thelia/thelia","fixedVersion":"2.1.3"}],"fix":{"url":"https://github.com/github/advisory-database/pull/8012","label":"github/advisory-database#8012"},"references":[{"type":"WEB","url":"https://github.com/github/advisory-database/pull/8012"},{"type":"WEB","url":"https://github.com/thelia/thelia/commit/028cfcf507cd8685772e156ec0c860034d407094"},{"type":"WEB","url":"https://github.com/thelia/thelia/commit/71c1cee66d8f2e515e82478f792879fa63843644"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/thelia/thelia/2015-04-13-1.yaml"},{"type":"PACKAGE","url":"https://github.com/thelia/thelia"},{"type":"WEB","url":"https://web.archive.org/web/20160502224630/http://thelia.net/version-2-1-3-with-security-fix"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-17T18:30:27.884445483Z"}}