CVE Published: 28/05/2021 |
CVE Updated: 16/09/2024 |
CVE Year: 2021 Source: twcert |
Vendor: SysJust |
Product: CTS Web Status : PUBLISHED
CVE-2021-32543 Description
The CTS Web transaction system related to authentication management is implemented incorrectly. After login, remote attackers can manipulate cookies to access other accounts and trade in the stock market with spoofed identity.
Metrics
CVSS Version: 3.1 |
Base Score: 6.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N