Intel

AIKIDO-2025-10877

verbb/social-login is vulnerable to Improper Authentication

Improper Authentication Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

91

Critical Risk

This Affects:

PHPverbb/social-login
1.0.0 - 1.0.23
Fixed in 1.0.24
2.0.0 - 2.0.11
Fixed in 2.0.12

TL;DR

Affected versions of this package allow inactive users to log in because the authentication logic does not properly enforce the account status. This improper authentication lets deactivated accounts regain access when they should be blocked.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

verbb/social-login is vulnerable to Improper Authentication in versions 1.0.0 - 1.0.23 and 2.0.0 - 2.0.11.

How to fix this

Upgrade the verbb/social-login library to the patch version.