PT-2021-23581 · Unknown · 4Mosan Gcb Doctor

·

CVE-2021-42338

·

Published

2021-11-19

·

Updated

2022-08-09

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions 4MOSAn GCB Doctor (affected versions not specified)
Description The issue is related to improper validation of Cookie on the login page, allowing an unauthenticated remote attacker to bypass authentication by code injection in the cookie. This enables the attacker to arbitrarily manipulate the system or interrupt services by uploading and executing arbitrary files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42338

Affected Products

4Mosan Gcb Doctor