PT-2024-17911 · Unknown · Electronic Official Document Management System

Liyu Hung

+1

·

Published

2024-12-31

·

Updated

2025-01-02

·

CVE-2024-13061

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Electronic Official Document Management System (affected versions not specified)
Description The Electronic Official Document Management System has an Authentication Bypass issue. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be used to log into the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2024-13061

Affected Products

Electronic Official Document Management System