A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass
security restriction using a specially crafted packet and retrieve a valid
session token for the targeted account.
Credits
Brian CHERVY, System Engineer from Antiane, Réunion Team, https://antiane.com