ZeroHour

CVE-2023-6451

CVSS 3.1
7.5 high
EPSS
<1%p43
Published
()
Modified
Description

Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's authentication mechanisms.

Vendors
alayacare
Products
procura
Weakness
CWE-1394, CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.