PT-2023-20570 · Ubika · Ubika Waap Gateway/Cloud

Published

2023-03-08

·

Updated

2023-03-15

·

CVE-2023-26261

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UBIKA WAAP Gateway/Cloud versions prior to 6.11.0 UBIKA WAAP Gateway/Cloud versions prior to 6.5.6-patch15
Description A blind XPath injection issue leads to an authentication bypass by stealing the session of another connected user.
Recommendations For versions prior to 6.11.0, update to WAAP Gateway & Cloud 6.11.0. For versions prior to 6.5.6-patch15, update to WAAP Gateway & Cloud 6.5.6-patch15.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-26261

Affected Products

Ubika Waap Gateway/Cloud