CVE-2019-16133

MEDIUM

Eteams OA <4.0.34 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwords of all employees in the company can be obtained by an ordinary account. Specifically, the attacker sends a jsessionid value for URIs under app/profile/summary/.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
http://www.iwantacve.cn/index.php/archives/271/

Scores

CVSS v3 6.5
EPSS 0.0103
EPSS Percentile 59.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-613
Status published
Products (1)
weaver/eteams_oa 4.0.34
Published Sep 09, 2019
Tracked Since Feb 18, 2026