Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x7xc-36fh-7mvr

Опубликовано: 27 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies and gain access to sensitive internal information.

TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies and gain access to sensitive internal information.

EPSS

Процентиль: 91%
0.06873
Низкий

7.5 High

CVSS3

Дефекты

CWE-1004

Связанные уязвимости

CVSS3: 7.5
nvd
6 дней назад

TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies and gain access to sensitive internal information.

EPSS

Процентиль: 91%
0.06873
Низкий

7.5 High

CVSS3

Дефекты

CWE-1004