Session Management Flaw in Seeyon Zhiyuan OA Web Application System
CVE-2021-4461
What is CVE-2021-4461?
The Seeyon Zhiyuan OA Web Application System, up to version 7.0 SP1, contains a vulnerability in its session management due to improper decoding and parsing of the enc parameter. An attacker can exploit this flaw to manipulate session attributes without proper authentication or authorization, allowing them to assign sessions to arbitrary user IDs. Active exploitation attempts have been reported, raising significant concerns for user data integrity and security.
Affected Version(s)
Zhiyuan OA Web Application System 0 <= 7.0 SP1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
