vendor:
wh-em.com upload
by:
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: wh-em.com upload
Affected Version From: 7
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Authentication Bypass Vulnerability in wh-em.com upload
The wh-em.com upload application fails to adequately verify user-supplied input used for cookie-based authentication, allowing attackers to gain administrative access to the affected application.
Mitigation:
It is recommended to apply the latest patches or updates from the vendor to fix this vulnerability. Additionally, strong and unique passwords should be used for administrative accounts.