Vulnerability Description
An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter completely by introducing a specially crafted request with relative path segments.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Docmosis | Tornado | < 2.9.5 |
Related Weaknesses (CWE)
References
- https://frycos.github.io/vulns4free/2023/01/24/0days-united-nations.htmlExploitThird Party Advisory
- https://resources.docmosis.com/content/documentation/tornado-v2-9-5-release-noteRelease Notes
- https://frycos.github.io/vulns4free/2023/01/24/0days-united-nations.htmlExploitThird Party Advisory
- https://resources.docmosis.com/content/documentation/tornado-v2-9-5-release-noteRelease Notes
FAQ
What is CVE-2023-25264?
CVE-2023-25264 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter completely by introducing a specially crafted request with re...
How severe is CVE-2023-25264?
CVE-2023-25264 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-25264?
Check the references section above for vendor advisories and patch information. Affected products include: Docmosis Tornado.