PT-2023-20570 · Ubika · Ubika Waap Gateway/Cloud

Publicado

2023-03-08

·

Atualizado

2023-03-15

·

CVE-2023-26261

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UBIKA WAAP Gateway/Cloud versions prior to 6.11.0 UBIKA WAAP Gateway/Cloud versions prior to 6.5.6-patch15
Description A blind XPath injection issue leads to an authentication bypass by stealing the session of another connected user.
Recommendations For versions prior to 6.11.0, update to WAAP Gateway & Cloud 6.11.0. For versions prior to 6.5.6-patch15, update to WAAP Gateway & Cloud 6.5.6-patch15.

Correção

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-26261

Produtos afetados

Ubika Waap Gateway/Cloud