CVE-2021-42338
4MOSAn GCB Doctor - Improper Authorization
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 9.8EPSS 5.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
19 nov 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrarily manipulate the system or interrupt services by upload and execution of arbitrary files.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
4MOSAn · GCB Doctor¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →