Authentication Bypass in 2100 Technology's Electronic Official Document Management System
CVE-2024-13061

9.8CRITICAL

What is CVE-2024-13061?

The Electronic Official Document Management System developed by 2100 Technology has an authentication bypass vulnerability that could be exploited by remote attackers. Despite an IP whitelist enforced for API interactions regarding user token queries, attackers may still manipulate the server's response mechanisms to obtain tokens from arbitrary users. This exploitation leads to unauthorized access to the system, enabling attackers to log in as legitimate users, which poses severe security risks for organizations relying on this document management solution. It emphasizes the need for organizations to assess their security measures surrounding user authentication and API access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Official Document Management System 0 < 5.0.86.9

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.