The CTS Web transaction system related to authentication management is implemented incorrectly. After login, remote attackers can manipulate cookies to access other accounts and trade in the stock market with spoofed identity.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-19389 | The CTS Web transaction system related to authentication management is implemented incorrectly. After login, remote attackers can manipulate cookies to access other accounts and trade in the stock market with spoofed identity. |
Fixes
Solution
Update CTS to version released after 2021.3.25
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T22:24:59.184Z
Reserved: 2021-05-10T00:00:00
Link: CVE-2021-32543
No data.
Status : Modified
Published: 2021-05-28T08:15:07.137
Modified: 2024-11-21T06:07:14.103
Link: CVE-2021-32543
No data.
OpenCVE Enrichment
No data.
EUVD