CVE-2021-22860
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
17/03/2021
Last modified:
23/03/2021
Description
EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vulnerability allows remote attacker to obtain users’ credential information without logging in the system, and further acquire the privileged permissions and execute arbitrary commends.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:eic:e-document_system:2.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:eic:e-document_system:3.0.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



