vendor:
bgERP
by:
nu11secur1ty
7.5
CVSS
HIGH
Cookie Session vulnerability & Cross-Site Scripting (XSS)
CWE
Product Name: bgERP
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2023
bgERP v22.31 (Orlovets) – Cookie Session vulnerability & Cross-Site Scripting (XSS)
The bgERP system suffers from unsecured login cookies in which cookies are stored as very sensitive login and also login session information! The attacker can trick the already login user and can steal the already generated cookie from the system and can do VERY DANGEROUS things with the already stored sensitive information. This can be very expensive for all companies which are using this system, please be careful! Also, this system has a vulnerable search parameter for XSS-Reflected attacks!