PT-2021-23581 · Unknown · 4Mosan Gcb Doctor

Meng Yi Chou

·

Published

2021-11-19

·

Updated

2022-08-09

·

CVE-2021-42338

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions 4MOSAn GCB Doctor (affected versions not specified)
Description The issue is related to improper validation of Cookie on the login page, allowing an unauthenticated remote attacker to bypass authentication by code injection in the cookie. This enables the attacker to arbitrarily manipulate the system or interrupt services by uploading and executing arbitrary files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-42338

Affected Products

4Mosan Gcb Doctor