vendor:
CitrusDB
by:
Unknown
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: CitrusDB
Affected Version From: CitrusDB 0.3.6
Affected Version To: Unknown
Patch Exists: No
Related CWE: Not provided
CPE: a:citrusdb_project:citrusdb:0.3.6
Platforms Tested: Not provided
Unknown
CitrusDB Authentication Bypass Vulnerability
An attacker can exploit an authentication bypass vulnerability in CitrusDB by using a static value during the creation of user cookie information. This allows the attacker to log in as any existing user, including the 'admin' account.
Mitigation:
Upgrade to a patched version of CitrusDB. Implement proper input validation and authentication mechanisms.