Security Advisory

CVE-2021-42115

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-11-30 11:28:07
Last updated 2024-08-04 03:22:25
Assigner NCSC.ch
CVSS score 8.1
State PUBLISHED

Description

Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authenticated user via stealing and injecting the session- independent and static cookie UID.