Vulnerabilities > CVE-2021-38618 - Unspecified vulnerability in Gfos Workforce Management 4.8.272.1
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
In GFOS Workforce Management 4.8.272.1, the login page of application is prone to authentication bypass, allowing anyone (who knows a user's credentials except the password) to get access to an account. This occurs because of JSESSIONID mismanagement.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |