CVE-2021-42338

CRITICAL

4mosan gcb_doctor < 20210708 - Unauthenticated Authentication Bypass and Arbitrary File Upload via Cookie Injection

Title source: llm
STIX 2.1

Description

4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrarily manipulate the system or interrupt services by upload and execution of arbitrary files.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-5313-45bde-1.html

Scores

CVSS v3 9.8
EPSS 0.0563
EPSS Percentile 91.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-285 CWE-287
Status published
Products (1)
4mosan/gcb_doctor < 20210708
Published Nov 19, 2021
Tracked Since Feb 18, 2026