PT-2022-17340 · Unknown · Freetakserver

Securitybits-Io

·

Published

2022-03-10

·

Updated

2022-03-22

·

CVE-2022-25510

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeTAKServer version 1.9.8
Description The issue concerns a hardcoded Flask secret key in FreeTAKServer, which allows attackers to create crafted cookies. This can lead to bypassing authentication or escalating privileges.
Recommendations For FreeTAKServer version 1.9.8, consider regenerating the Flask secret key to prevent attackers from creating crafted cookies. As a temporary workaround, restrict access to sensitive areas of the application to minimize the risk of exploitation.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25510
GHSA-F897-875P-23X7
PYSEC-2022-43135

Affected Products

Freetakserver