CVE-2024-13061 Information
Jan 02, 2025
cve
Description
The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users which can then be used to log into the system.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://www.twcert.org.tw/en/cp-139-8340-d8b16-2.html https://www.twcert.org.tw/tw/cp-132-8339-570fa-1.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: