Description
In GFOS Workforce Management 4.8.272.1, the login page of application is prone to authentication bypass, allowing anyone (who knows a user's credentials except the password) to get access to an account. This occurs because of JSESSIONID mismanagement.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-25058 | In GFOS Workforce Management 4.8.272.1, the login page of application is prone to authentication bypass, allowing anyone (who knows a user's credentials except the password) to get access to an account. This occurs because of JSESSIONID mismanagement. |
References
History
Fri, 30 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-30T16:01:43.556Z
Reserved: 2021-08-13T00:00:00.000Z
Link: CVE-2021-38618
No data.
Status : Modified
Published: 2021-10-04T18:15:09.387
Modified: 2025-05-30T16:15:28.733
Link: CVE-2021-38618
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD