Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's authentication mechanisms.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-02-16 04:15
Updated : 2024-02-16 13:37
NVD link : CVE-2023-6451
Mitre link : CVE-2023-6451
CVE.ORG link : CVE-2023-6451
JSON object : View
Products Affected
No product.
CWE
CWE-1394
Use of Default Cryptographic Key