Vulnerability Description
In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the session of another connected user. The fixed versions are WAAP Gateway & Cloud 6.11.0 and 6.5.6-patch15.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubikasec | Waap Cloud | < 6.11.0 |
| Ubikasec | Waap Gateway | < 6.11.0 |
Related Weaknesses (CWE)
References
- https://documentation.ubikasec.com/x/CQDAAwProduct
- https://gist.github.com/Jakick/7d1635b886654ddd0e476b3c79a7ba9fThird Party Advisory
- https://documentation.ubikasec.com/x/CQDAAwProduct
- https://gist.github.com/Jakick/7d1635b886654ddd0e476b3c79a7ba9fThird Party Advisory
FAQ
What is CVE-2023-26261?
CVE-2023-26261 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the session of another connected user. The fixed versions are WAAP Gateway & Cloud 6.11....
How severe is CVE-2023-26261?
CVE-2023-26261 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-26261?
Check the references section above for vendor advisories and patch information. Affected products include: Ubikasec Waap Cloud, Ubikasec Waap Gateway.