Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-0947

Опубликовано: 27 июн. 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Session Credential Falsification through Manipulation, Accessing/Intercepting/Modifying HTTP Cookies, Manipulating Opaque Client-based Data Tokens.This issue affects Elektraweb: before v17.0.68.

EPSS

Процентиль: 39%
0.00174
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-565

Связанные уязвимости

CVSS3: 9.8
github
больше 1 года назад

Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Session Credential Falsification through Manipulation, Accessing/Intercepting/Modifying HTTP Cookies, Manipulating Opaque Client-based Data Tokens.This issue affects Elektraweb: before v17.0.68.

EPSS

Процентиль: 39%
0.00174
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-565