Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-38618

Опубликовано: 04 окт. 2021
Источник: nvd
CVSS3: 7.4
CVSS3: 8.1
CVSS2: 6.8
EPSS Низкий

Описание

In GFOS Workforce Management 4.8.272.1, the login page of application is prone to authentication bypass, allowing anyone (who knows a user's credentials except the password) to get access to an account. This occurs because of JSESSIONID mismanagement.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gfos:workforce_management:4.8.272.1:*:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.00255
Низкий

7.4 High

CVSS3

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

In GFOS Workforce Management 4.8.272.1, the login page of application is prone to authentication bypass, allowing anyone (who knows a user's credentials except the password) to get access to an account. This occurs because of JSESSIONID mismanagement.

EPSS

Процентиль: 49%
0.00255
Низкий

7.4 High

CVSS3

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo