CVE-2021-22860

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
17/03/2021
Last modified:
23/03/2021

Description

EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vulnerability allows remote attacker to obtain users’ credential information without logging in the system, and further acquire the privileged permissions and execute arbitrary commends.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eic:e-document_system:2.9:*:*:*:*:*:*:*
cpe:2.3:a:eic:e-document_system:3.0.2:*:*:*:*:*:*:*