CVE Vulnerabilities

CVE-2022-38297

Reliance on Cookies without Validation and Integrity Checking

Published: Sep 12, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.

Weakness

The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.

Affected Software

NameVendorStart VersionEnd Version
UcmsUcms_project1.6 (including)1.6 (including)

Potential Mitigations

References