Authentication Bypass in 2100 Technology's Electronic Official Document Management System
CVE-2024-13061
9.8CRITICAL
What is CVE-2024-13061?
The Electronic Official Document Management System developed by 2100 Technology has an authentication bypass vulnerability that could be exploited by remote attackers. Despite an IP whitelist enforced for API interactions regarding user token queries, attackers may still manipulate the server's response mechanisms to obtain tokens from arbitrary users. This exploitation leads to unauthorized access to the system, enabling attackers to log in as legitimate users, which poses severe security risks for organizations relying on this document management solution. It emphasizes the need for organizations to assess their security measures surrounding user authentication and API access.
Affected Version(s)
Official Document Management System 0 < 5.0.86.9
