PT-2022-12545 · Unknown · Vehicle Service Management System

P.L.Sanu

·

Published

2022-01-06

·

Updated

2022-01-13

·

CVE-2021-46067

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vehicle Service Management System version 1.0
Description The issue allows an attacker to steal cookies, leading to Full Account Takeover.
Recommendations For Vehicle Service Management System version 1.0, consider implementing additional security measures to protect user session cookies, such as using secure protocols for cookie transmission and storage, until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-46067

Affected Products

Vehicle Service Management System