PT-2022-9375 · Unknown · Agilia Link+
Published
2022-01-21
·
Updated
2022-08-30
·
CVE-2021-23196
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Agilia Link+ version 3.0
Description
The web application implements authentication and session management mechanisms exclusively on the client-side and does not protect authentication attributes sufficiently.
Recommendations
For Agilia Link+ version 3.0, consider implementing server-side authentication and session management mechanisms to protect authentication attributes sufficiently. As a temporary workaround, restrict access to sensitive areas of the web application to minimize the risk of exploitation.
Fix
Improper Authentication
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Agilia Link+