Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's authentication mechanisms.
Solution:
The product uses a default cryptographic key for potentially critical functionality.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://www.themissinglink.com.au/security-advisories/cve-2023-6451 | third party advisory |