Vulnerability Description
An issue was discovered in OverIT Geocall 6.3 before build 2:346977. An unauthenticated servlet allows an attacker to obtain a cookie of an authenticated user, and login to the web application.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Overit | Geocall | 6.3 |
References
- https://web.archive.org/web/20200327142627/https://www.quantumleap.it/geocall-v-Third Party Advisory
- https://www.quantumleap.it/geocall-v-6-3-multiple-vulnerabilities/Broken LinkThird Party Advisory
- https://web.archive.org/web/20200327142627/https://www.quantumleap.it/geocall-v-Third Party Advisory
- https://www.quantumleap.it/geocall-v-6-3-multiple-vulnerabilities/Broken LinkThird Party Advisory
FAQ
What is CVE-2019-5891?
CVE-2019-5891 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in OverIT Geocall 6.3 before build 2:346977. An unauthenticated servlet allows an attacker to obtain a cookie of an authenticated user, and login to the web application.
How severe is CVE-2019-5891?
CVE-2019-5891 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-5891?
Check the references section above for vendor advisories and patch information. Affected products include: Overit Geocall.