CVE-2024-6737

Published Jul 15, 2024

Last updated 4 months ago

Overview

Description
The access control in the Electronic Official Document Management System from 2100 TECHNOLOGY is not properly implemented, allowing remote attackers with regular privileges to access the account settings functionality and create an administrator account.
Source
twcert@cert.org.tw
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
NVD-CWE-Other
twcert@cert.org.tw
CWE-284

Social media

Hype score
Not currently trending

Configurations