Filtered by CWE-565
Total 65 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-20512 1 Cdatatec 22 Epon Cpe-wifi Devices Firmware, Fd108bn, Fd111hz and 19 more 2024-11-21 N/A
EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.
CVE-2018-19224 1 Laobancms 1 Laobancms 2024-11-21 N/A
An issue was discovered in LAOBANCMS 2.0. /admin/login.php allows spoofing of the id and guanliyuan cookies.
CVE-2012-5631 1 Freeipa 1 Freeipa 2024-11-21 8.8 High
ipa 3.0 does not properly check server identity before sending credential containing cookies
CVE-2024-9820 1 Dueclic 1 Wp 2fa With Telegram 2024-10-19 6.5 Medium
The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication.
CVE-2024-9970 2 New Type, Newtype 2 Flowmaster Bpm Plus, Flowmaster Bpm Plus 2024-10-17 8.8 High
The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie.