PT-2022-12545 · Unknown · Vehicle Service Management System
P.L.Sanu
·
Published
2022-01-06
·
Updated
2022-01-13
·
CVE-2021-46067
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vehicle Service Management System version 1.0
Description
The issue allows an attacker to steal cookies, leading to Full Account Takeover.
Recommendations
For Vehicle Service Management System version 1.0, consider implementing additional security measures to protect user session cookies, such as using secure protocols for cookie transmission and storage, until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vehicle Service Management System