PT-2025-40349 · Rocketsoftware · Trufusion Enterprise
Published
2025-10-02
·
Updated
2025-10-27
·
CVE-2025-27223
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TRUfusion Enterprise versions through 7.10.4.0
Description
The application uses a static key to encrypt the
COOKIEID, which serves as an authentication mechanism for certain endpoints, such as /trufusionPortal/getProjectList. This allows for the forging of cookies, potentially granting unauthorized access to sensitive internal information.Recommendations
Versions prior to 7.10.4.0 should be updated.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trufusion Enterprise