Loading vulnerability details…
CVSS v3.1
8.6
EPSS
0.53%
Published
Feb 16, 2024
Modified
Jan 9, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's authentication mechanisms.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:NWeaknesses (CWE)
Affected Products (1)
References (2)