ZeroHour

CVE-2019-16133

PoC
CVSS 3.1
6.5 medium
EPSS
1%p62
Published
()
Modified
Description

An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwords of all employees in the company can be obtained by an ordinary account. Specifically, the attacker sends a jsessionid value for URIs under app/profile/summary/.

Vendors
weaver
Products
eteams oa
Weakness
CWE-613
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.