CVE-2024-32832

Executive Summary

CVE-2024-32832 exposes a missing authorization flaw in Hamid Alinia's Login with phone number feature (versions <=1.6.93). Attackers can authenticate without proper credentials, enabling unauthorized access to user accounts and sensitive data. The vulnerability is not yet listed in CISA KEV, but mitigations include updating to the latest patch or disabling phone‑number login.


Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2025-08-31T04:15:48.243 - Last Modified: 2026-10-06T22:10:00.247

Original Description: Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.6.93.

"Great acts are made up of small deeds."

— Lao Tzu
Source: NVD