216.73.216.233

CVE-2024-13061

· Published 31/12/2024 12:15 · Modified 02/01/2025 02:15

Labels: CVE-2024-13061 2024-12-31CVE-2024-13061CWE-290[email protected]

Essential information

Published
31/12/2024 12:15
Modified
02/01/2025 02:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be used to log into the system.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References