4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrarily manipulate the system or interrupt services by upload and execution of arbitrary files.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-29312 | 4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrarily manipulate the system or interrupt services by upload and execution of arbitrary files. |
Fixes
Solution
Update 4MOSAn GCB Doctor version to 20210811 (v2.0)
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5313-45bde-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-17T00:21:46.974Z
Reserved: 2021-10-12T00:00:00
Link: CVE-2021-42338
No data.
Status : Modified
Published: 2021-11-19T09:15:06.683
Modified: 2024-11-21T06:27:38.233
Link: CVE-2021-42338
No data.
OpenCVE Enrichment
No data.
EUVD